VYPR

CMS Commander

by WordPress

CVEs (2)

  • CVE-2026-3334HigMar 21, 2026
    risk 0.57cvss 8.8epss 0.00

    The CMS Commander plugin for WordPress is vulnerable to SQL Injection via the 'or_blogname', 'or_blogdescription', and 'or_admin_email' parameters in all versions up to, and including, 2.288. This is due to insufficient escaping on the user supplied parameters and lack of…

  • CVE-2023-3325HigJun 20, 2023
    risk 0.46cvss 8.1epss 0.00

    The CMS Commander plugin for WordPress is vulnerable to authorization bypass due to the use of an insufficiently unique cryptographic signature on the 'cmsc_add_site' function in versions up to, and including, 2.287. This makes it possible for unauthenticated attackers to the…