VYPR

Out-of-the-Box

by WordPress

CVEs (2)

  • CVE-2026-93031HigSep 18, 2026
    risk 0.57cvss 8.8epss 0.01

    The WP Cloud Plugins Use-your-Drive, Out-of-the-Box, Share-one-Drive, and Lets-Box plugins for WordPress are vulnerable to Arbitrary File Upload in all versions from 2.0 up to, and including, 3.8.3 via the download_file_to_uploads function. This is due to the import action being…

  • CVE-2021-42547MedDec 13, 2021
    risk 0.31cvss 4.7epss 0.01

    Insufficient Input Validation in the search functionality of Wordpress plugin Out-of-the-Box prior to 1.20.3 allows unauthenticated user to craft a reflected Cross-Site Scripting attack.