VYPR

Plugin

by WordPress

CVEs (7)

  • CVE-2021-24638CriSep 20, 2021
    risk 0.59cvss 9.1epss 0.02

    The OMGF WordPress plugin before 4.5.4 does not escape or validate the handle parameter of the REST API, which allows unauthenticated users to perform path traversal and overwrite arbitrary CSS file with Google Fonts CSS, or download fonts uploaded on Google Fonts website.

  • CVE-2022-2557HigAug 22, 2022
    risk 0.57cvss 8.8epss 0.02

    The Team WordPress plugin before 4.1.2 contains a file which could allow any authenticated users to download arbitrary files from the server via a path traversal vector. Furthermore, the file will also be deleted after its content is returned to the user

  • CVE-2021-24639HigSep 20, 2021
    risk 0.53cvss 8.1epss 0.01

    The OMGF WordPress plugin before 4.5.4 does not enforce path validation, authorisation and CSRF checks in the omgf_ajax_empty_dir AJAX action, which allows any authenticated users to delete arbitrary files or folders on the server.

  • CVE-2021-24947MedFeb 7, 2022
    risk 0.42cvss 6.5epss 0.03

    The RVM WordPress plugin before 6.4.2 does not have proper authorisation, CSRF checks and validation of the rvm_upload_regions_file_path parameter in the rvm_import_regions AJAX action, allowing any authenticated user, such as subscriber, to read arbitrary files on the web server

  • CVE-2023-25972MedJun 15, 2023
    risk 0.38cvss 5.9epss 0.00

    Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in IKSWEB WordPress Старт plugin <= 3.7 versions.

  • CVE-2024-9883MedNov 5, 2024
    risk 0.31cvss 4.8epss 0.00

    The Pods WordPress plugin before 3.2.7.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite…

  • CVE-2026-14482HigJul 8, 2026
    risk 0.00cvss 8.8epss 0.01

    The 多说社会化评论框 plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.2. The vulnerability exists due to a missing capability and nonce check on a directly web-accessible API endpoint, combined with a trivially forgeable…