VYPR

iControlWP

by WordPress

CVEs (2)

  • CVE-2026-34901CriJun 15, 2026
    risk 0.64cvss 9.8epss 0.00

    Unauthenticated Privilege Escalation in iControlWP <= 5.5.3 versions.

  • CVE-2024-13742CriJan 30, 2025
    risk 0.64cvss 9.8epss 0.01

    The iControlWP – Multiple WordPress Site Manager plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 4.4.5 via deserialization of untrusted input from the reqpars parameter. This makes it possible for unauthenticated attackers to…