← Back

Wpexperts

wpexperts

49 CVEs • 17 products

Products (17)

Click to collapse
Toggle

CVEs (49)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Wpexperts
1Post Smtp
May 21, 2025
Sep 26, 2022
N/A· v4
7.2 HIGH· v3
N/A· v2
The Post SMTP Mailer/Email Log WordPress plugin before 2.1.7 does not have proper authorisation in some AJAX actions, which could allow high privilege users such as admin to perform blind SSRF on multisite installations...Show more
The Post SMTP Mailer/Email Log WordPress plugin before 2.1.7 does not have proper authorisation in some AJAX actions, which could allow high privilege users such as admin to perform blind SSRF on multisite installations for example.Show less
1Wpexperts
1Post Smtp
Nov 21, 2024
Sep 16, 2022
N/A· v4
4.8 MEDIUM· v3
N/A· v2
The Post SMTP Mailer/Email Log WordPress plugin before 2.1.4 does not escape some of its settings before outputting them in the admins dashboard, allowing high privilege users to perform Cross-Site Scripting attacks agai...Show more
The Post SMTP Mailer/Email Log WordPress plugin before 2.1.4 does not escape some of its settings before outputting them in the admins dashboard, allowing high privilege users to perform Cross-Site Scripting attacks against other users even when the unfiltered_html capability is disallowed.Show less
1Wpexperts
1Wp Contact Slider
Nov 21, 2024
Jul 4, 2022
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
The WP Contact Slider WordPress plugin before 2.4.7 does not sanitize and escape the Text to Display settings of sliders, which could allow high privileged users such as editor and above to perform Cross-Site Scripting a...Show more
The WP Contact Slider WordPress plugin before 2.4.7 does not sanitize and escape the Text to Display settings of sliders, which could allow high privileged users such as editor and above to perform Cross-Site Scripting attacks even when the unfiltered_html is disallowedShow less
1Wpexperts
1New User Approve
Nov 21, 2024
Jun 27, 2022
N/A· v4
4.3 MEDIUM· v3
4.3 MEDIUM· v2
The New User Approve WordPress plugin before 2.4 does not have CSRF check in place when updating its settings and adding invitation codes, which could allow attackers to add invitation codes (for bypassing the provided r...Show more
The New User Approve WordPress plugin before 2.4 does not have CSRF check in place when updating its settings and adding invitation codes, which could allow attackers to add invitation codes (for bypassing the provided restrictions) and to change plugin settings by tricking admin users into visiting specially crafted websites.Show less
1Wpexperts
1All In One Login
Jan 14, 2026
May 30, 2022
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
The Change wp-admin login WordPress plugin before 1.1.0 does not properly check for authorisation and is also missing CSRF check when updating its settings, which could allow unauthenticated users to change the settings....Show more
The Change wp-admin login WordPress plugin before 1.1.0 does not properly check for authorisation and is also missing CSRF check when updating its settings, which could allow unauthenticated users to change the settings. The attacked could also be performed via a CSRF vectorShow less
1Wpexperts
1Mycred
Oct 17, 2025
Apr 25, 2022
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
The myCred WordPress plugin before 2.4.3.1 does not have authorisation and CSRF checks in its mycred-tools-import-export AJAX action, allowing any authenticated user to call and and retrieve the list of email address pre...Show more
The myCred WordPress plugin before 2.4.3.1 does not have authorisation and CSRF checks in its mycred-tools-import-export AJAX action, allowing any authenticated user to call and and retrieve the list of email address present in the blogShow less
1Wpexperts
1Mycred
Oct 17, 2025
Apr 25, 2022
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
The myCred WordPress plugin before 2.4.3.1 does not have any authorisation and CSRF checks in the mycred-tools-import-export AJAX action, allowing any authenticated users, such as subscribers, to call it and import mycre...Show more
The myCred WordPress plugin before 2.4.3.1 does not have any authorisation and CSRF checks in the mycred-tools-import-export AJAX action, allowing any authenticated users, such as subscribers, to call it and import mycred setup, thus creating badges, managing points or creating arbitrary posts.Show less
1Wpexperts
1Mycred
Oct 17, 2025
Apr 25, 2022
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
The myCred WordPress plugin before 2.4.4.1 does not have any authorisation in place in its mycred-tools-select-user AJAX action, allowing any authenticated user, such as subscriber to call and retrieve all email addresse...Show more
The myCred WordPress plugin before 2.4.4.1 does not have any authorisation in place in its mycred-tools-select-user AJAX action, allowing any authenticated user, such as subscriber to call and retrieve all email addresses from the blogShow less
1Wpexperts
1Mycred
Oct 17, 2025
Nov 29, 2021
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
The myCred WordPress plugin before 2.3 does not validate or escape the fields parameter before using it in a SQL statement, leading to an SQL injection exploitable by any authenticated user