VYPR

True Ranker

by WordPress

CVEs (2)

  • CVE-2021-39312HigDec 14, 2021
    risk 0.58cvss 7.5epss 0.78

    The True Ranker plugin <= 2.2.2 for WordPress allows arbitrary files, including sensitive configuration files such as wp-config.php, to be accessed via the src parameter found in the ~/admin/vendor/datatables/examples/resources/examples.php file.

  • CVE-2026-1085MedMar 7, 2026
    risk 0.28cvss 4.3epss 0.00

    The True Ranker plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.2.9. This is due to missing nonce validation on the seolocalrank-signout action. This makes it possible for unauthenticated attackers to disconnect the…