VYPR

Wp Promoter

by WordPress

CVEs (1)

  • CVE-2026-9014MedMay 27, 2026
    risk 0.34cvss 5.3epss

    The WP Promoter plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the reset_stats() function in versions up to, and including, 1.3. The function is hooked to both the wp_ajax_wpp-reset_stats and…