VYPR
Vendor

Wpcerber

Products
2
CVEs
4
Across products
4
Status
Private

Products

2

Recent CVEs

4
  • CVE-2021-37597CriAug 19, 2021
    risk 0.64cvss 9.8epss 0.02

    WP Cerber before 8.9.3 allows MFA bypass via wordpress_logged_in_[hash] manipulation.

  • CVE-2016-10990MedSep 17, 2019
    risk 0.40cvss 6.1epss 0.01

    The wp-cerber plugin before 2.7 for WordPress has XSS via the X-Forwarded-For HTTP header.

  • CVE-2021-37598MedAug 19, 2021
    risk 0.35cvss 5.3epss 0.02

    WP Cerber before 8.9.3 allows bypass of /wp-json access control via a trailing ? character.

  • CVE-2022-4100MedAug 31, 2024
    risk 0.27cvss 5.3epss 0.00

    The WP Cerber Security plugin for WordPress is vulnerable to IP Protection bypass in versions up to, and including 9.4 due to the plugin improperly checking for a visitor's IP address. This makes it possible for an attacker whose IP address has been blocked to bypass this…