Wpexpertplugins
wpexpertplugins
5 CVEs • 1 product
Products (1)
Click to collapseToggle
Products (1)
Click to collapse
CVEs (5)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Wpexpertplugins 1Post Meta Data Manager Apr 8, 2026 Mar 8, 2025 N/A· v4 7.2 HIGH· v3 N/A· v2 The Post Meta Data Manager plugin for WordPress is vulnerable to multisite privilege escalation in all versions up to, and including, 1.4.4. This is due to the plugin not properly verifying the existence of a multisite i...Show more |
1Wpexpertplugins 1Post Meta Data Manager Apr 8, 2026 Jul 2, 2024 N/A· v4 5.4 MEDIUM· v3 N/A· v2 The Post Meta Data Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘$meta_key’ parameter in all versions up to, and including, 1.2.3 due to insufficient input sanitization and output esc...Show more |
1Wpexpertplugins 1Post Meta Data Manager Apr 8, 2026 Nov 21, 2023 N/A· v4 8.8 HIGH· v3 N/A· v2 The Post Meta Data Manager plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.2.1. This is due to missing nonce validation on the pmdm_wp_ajax_delete_meta, pmdm_wp_de...Show more |
1Wpexpertplugins 1Post Meta Data Manager Apr 8, 2026 Oct 28, 2023 N/A· v4 7.5 HIGH· v3 N/A· v2 The Post Meta Data Manager plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the pmdm_wp_delete_user_meta, pmdm_wp_delete_term_meta, and pmdm_wp_ajax_delete_met...Show more |
1Wpexpertplugins 1Post Meta Data Manager Apr 8, 2026 Oct 28, 2023 N/A· v4 8.8 HIGH· v3 N/A· v2 The Post Meta Data Manager plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the pmdm_wp_change_user_meta and pmdm_wp_change_post_meta functions in versions up t...Show more |