VYPR

Zapier

by WordPress

CVEs (2)

  • CVE-2024-13411MedMar 26, 2025
    risk 0.42cvss 6.4epss 0.00

    The Zapier for WordPress plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 1.5.1 via the updated_user() function. This makes it possible for authenticated attackers, with Subscriber-level access and above, to make web requests to arbitrary locations originating from the web application which can be used to query and modify information from internal services.

  • CVE-2025-50010MedJun 20, 2025
    risk 0.35cvss 5.4epss 0.00

    Missing Authorization vulnerability in Zapier Zapier for WordPress zapier allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Zapier for WordPress: from n/a through <= 1.5.2.