Content Egg
by WordPress
CVEs (6)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-15979 | Hig | 0.53 | 8.1 | 0.01 | Aug 5, 2026 | The Content Egg – Affiliate Product Importer & Price Comparison plugin for WordPress is vulnerable to Arbitrary File Deletion via Path Traversal in versions up to and including 11.3.0. This is due to insufficient validation of the 'img_file' field within the cegg_data post… | ||
| CVE-2026-96832 | Hig | 0.47 | 7.2 | — | Sep 30, 2026 | Shop manager PHP Object Injection in Content Egg <= 6.3.1 versions. | ||
| CVE-2025-47536 | Hig | 0.47 | 7.2 | 0.00 | Aug 14, 2025 | Deserialization of Untrusted Data vulnerability in keywordrush Content Egg content-egg allows Object Injection.This issue affects Content Egg: from n/a through <= 7.0.0. | ||
| CVE-2026-92424 | Med | 0.44 | 6.8 | 0.00 | Sep 30, 2026 | The Content Egg WordPress plugin before 11.9.0 does not verify that a user running its bulk content-import feature is authorized for the import preset they select, and switches to the preset author's identity before creating the resulting post, allowing users with… | ||
| CVE-2022-0428 | Med | 0.40 | 6.1 | 0.01 | May 2, 2022 | The Content Egg WordPress plugin before 5.3.0 does not sanitise and escape the page parameter before outputting back in an attribute in the Autoblogging admin dashboard, leading to a Reflected Cross-Site Scripting | ||
| CVE-2022-25952 | Med | 0.28 | 4.3 | 0.00 | Nov 3, 2022 | Cross-Site Request Forgery (CSRF) vulnerability in Keywordrush Content Egg plugin <= 5.4.0 on WordPress. |
- risk 0.53cvss 8.1epss 0.01
The Content Egg – Affiliate Product Importer & Price Comparison plugin for WordPress is vulnerable to Arbitrary File Deletion via Path Traversal in versions up to and including 11.3.0. This is due to insufficient validation of the 'img_file' field within the cegg_data post…
- risk 0.47cvss 7.2epss —
Shop manager PHP Object Injection in Content Egg <= 6.3.1 versions.
- risk 0.47cvss 7.2epss 0.00
Deserialization of Untrusted Data vulnerability in keywordrush Content Egg content-egg allows Object Injection.This issue affects Content Egg: from n/a through <= 7.0.0.
- risk 0.44cvss 6.8epss 0.00
The Content Egg WordPress plugin before 11.9.0 does not verify that a user running its bulk content-import feature is authorized for the import preset they select, and switches to the preset author's identity before creating the resulting post, allowing users with…
- risk 0.40cvss 6.1epss 0.01
The Content Egg WordPress plugin before 5.3.0 does not sanitise and escape the page parameter before outputting back in an attribute in the Autoblogging admin dashboard, leading to a Reflected Cross-Site Scripting
- risk 0.28cvss 4.3epss 0.00
Cross-Site Request Forgery (CSRF) vulnerability in Keywordrush Content Egg plugin <= 5.4.0 on WordPress.