VYPR

ManageWP Worker

by WordPress

CVEs (3)

  • CVE-2026-18052HigAug 22, 2026
    risk 0.53cvss 8.1epss 0.00

    The ManageWP Worker WordPress plugin before 4.9.37 does not bind the account being logged in to the signature which authorises the login, nor prevent an already used login link from being replayed, allowing attackers who obtain such a link to gain a session as any user on the…

  • CVE-2026-39463HigJun 15, 2026
    risk 0.46cvss 7.1epss 0.00

    Unauthenticated Cross Site Scripting (XSS) in ManageWP Worker <= 4.9.31 versions.

  • CVE-2026-3718HigMay 14, 2026
    risk 0.40cvss 7.2epss 0.00

    The ManageWP Worker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'MWP-Key-Name' HTTP request header in all versions up to, and including, 4.9.31. This is due to insufficient input sanitization and output escaping of attacker-controlled header values.…