VYPR

by WordPress

CVEs (3)

  • CVE-2024-11231MedNov 23, 2024
    risk 0.35cvss 6.4epss 0.00

    The 우커머스 네이버페이 plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's mnp_purchase shortcode in all versions up to, and including, 3.3.7 due to insufficient input sanitization and output escaping on user supplied attributes. This…

  • CVE-2026-13597CriJul 27, 2026
    risk 0.00cvss 9.1epss 0.00

    The 微信二维码登陆 WordPress plugin through 1.3 does not properly validate WeChat webhook requests, as its signature check always passes, and it discloses the generated login code in the webhook response. This allows an unauthenticated attacker to forge a login event for…

  • CVE-2026-65536MedJul 23, 2026
    risk 0.00cvss 6.5epss 0.00

    Unauthenticated Cross Site Request Forgery (CSRF) in افزونه حمل و نقل ووکامرس (پست پیشتاز و سفارشی، پیک موتوری) <= 4.4.5 versions.