VYPR

Squeeze

by WordPress

Source repositories

CVEs (5)

  • CVE-2025-31002CriApr 9, 2025
    risk 0.59cvss 9.1epss 0.01

    Unrestricted Upload of File with Dangerous Type vulnerability in Bogdan Bendziukov Squeeze squeeze allows Using Malicious Files.This issue affects Squeeze: from n/a through <= 1.6.

  • CVE-2024-35767CriJun 21, 2024
    risk 0.59cvss 9.1epss 0.00

    Unrestricted Upload of File with Dangerous Type vulnerability in Bogdan Bendziukov Squeeze allows Code Injection.This issue affects Squeeze: from n/a through 1.4.

  • CVE-2026-16985HigAug 10, 2026
    risk 0.57cvss 8.8epss 0.00

    The Squeeze WordPress plugin before 1.7.12 does not validate the file type or extension of the per-size image data written by one of its attachment-update actions, allowing users with the upload_files capability (Author and above) to write an executable PHP file into the…

  • CVE-2026-32415MedMar 13, 2026
    risk 0.33cvss 5.0epss 0.00

    Path Traversal: '.../...//' vulnerability in Bogdan Bendziukov Squeeze squeeze allows Path Traversal.This issue affects Squeeze: from n/a through <= 1.7.7.

  • CVE-2025-31003LowApr 9, 2025
    risk 0.18cvss 2.7epss 0.01

    Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Bogdan Bendziukov Squeeze squeeze allows Retrieve Embedded Sensitive Data.This issue affects Squeeze: from n/a through <= 1.6.