VYPR
Vendor

AHAthat

Products
1
CVEs
2
Across products
1
Status
Private

Products

1

Recent CVEs

2
  • CVE-2025-4337MedMay 6, 2025
    risk 0.28cvss 4.3epss 0.00

    The AHAthat Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.6. This is due to missing or incorrect nonce validation on the aha_plugin_page() function. This makes it possible for unauthenticated attackers to delete AHA pages via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

  • CVE-2024-11269May 15, 2025
    risk 0.00cvss epss 0.00

    The AHAthat Plugin WordPress plugin through 1.6 does not sanitize and escape a parameter before using it in a SQL statement, allowing Admin to perform SQL injection attacks.