VYPR

Anti Malware Security And Bruteforce Firewall

by WordPress

CVEs (7)

  • CVE-2024-22144CriApr 25, 2024
    risk 0.59cvss 9.0epss 0.01

    Improper Control of Generation of Code ('Code Injection') vulnerability in Eli Scheetz Anti-Malware Security and Brute-Force Firewall gotmls allows Code Injection.This issue affects Anti-Malware Security and Brute-Force Firewall: from n/a through 4.21.96.

  • CVE-2026-39478HigJun 15, 2026
    risk 0.57cvss 8.8epss 0.00

    Contributor PHP Object Injection in Anti-Malware Security and Brute-Force Firewall <= 4.23.87 versions.

  • CVE-2021-47977HigMay 16, 2026
    risk 0.49cvss 7.5epss 0.01

    WordPress Plugin Anti-Malware Security and Bruteforce Firewall 4.20.59 contains a directory traversal vulnerability that allows unauthenticated attackers to read arbitrary files by manipulating the file parameter. Attackers can send requests to the duplicator_download action via…

  • CVE-2022-2599MedAug 29, 2022
    risk 0.40cvss 6.1epss 0.01

    The Anti-Malware Security and Brute-Force Firewall WordPress plugin before 4.21.83 does not sanitise and escape some parameters before outputting them back in an admin dashboard, leading to Reflected Cross-Site Scripting

  • CVE-2022-0953MedApr 25, 2022
    risk 0.40cvss 6.1epss 0.03

    The Anti-Malware Security and Brute-Force Firewall WordPress plugin before 4.20.96 does not sanitise and escape the QUERY_STRING before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting in browsers which do not encode characters

  • CVE-2025-11705MedOct 29, 2025
    risk 0.35cvss 6.5epss 0.01

    The Anti-Malware Security and Brute-Force Firewall plugin for WordPress is vulnerable to Arbitrary File Read in all versions up to, and including, 4.23.81 due to a missing capability check combined with an information exposure in several GOTMLS_* AJAX actions. This makes it…

  • CVE-2021-25101MedFeb 21, 2022
    risk 0.31cvss 4.8epss 0.01

    The Anti-Malware Security and Brute-Force Firewall WordPress plugin before 4.20.94 does not sanitise and escape the POST data before outputting it back in attributes of an admin page, leading to a Reflected Cross-Site scripting. Due to the presence of specific parameter value,…