VYPR

Web Application Firewall

by TR7 Cyber Defense Inc.

CVEs (3)

  • CVE-2024-2172CriMar 13, 2024
    risk 0.64cvss 9.8epss 0.02

    The Malware Scanner plugin and the Web Application Firewall plugin for WordPress (both by MiniOrange) are vulnerable to privilege escalation due to a missing capability check on the mo_wpns_init() function in all versions up to, and including, 4.7.2 (for Malware Scanner) and…

  • CVE-2025-2418MedFeb 16, 2026
    risk 0.28cvss 4.3epss 0.00

    URL Redirection to Untrusted Site ('Open Redirect') vulnerability in TR7 Cyber ​​Defense Inc. Web Application Firewall allows Phishing. This issue affects Web Application Firewall: from 4.30 before v1.4.0.117.

  • CVE-2026-4770MedJul 2, 2026
    risk 0.00cvss 4.6epss 0.00

    Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in TR7 Cyber ​​Defense Inc. Web Application Firewall allows DOM-Based XSS. This issue affects Web Application Firewall: from v1.0.42.239 before v1.4.0.117.