Benjaminrojas / WP Editor
7 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2025-3294 | WP Editor <= 1.2.9.1 - Authenticated (Administrator+) Directory Traversal to Arbitrary File Update | HIGH | 7.2 | Apr 17, 2025 |
| CVE-2025-3295 | WP Editor <= 1.2.9.1 - Authenticated (Administrator+) Directory Traversal to Arbitrary File Read | MEDIUM | 4.9 | Apr 17, 2025 |
| CVE-2022-2446 | WP Editor <= 1.2.9 - Authenticated (Admin+) PHAR Deserialization | HIGH | 7.2 | Sep 13, 2024 |
| CVE-2024-24700 | WordPress WP Editor plugin <= 1.2.8 - Reflected Cross Site Scripting (XSS) vulnerability | HIGH | 7.1 | Mar 27, 2024 |
| CVE-2024-25591 | WordPress WP Editor plugin <=1.2.7 - Sensitive Data Exposure vulnerability | HIGH | 7.5 | Mar 17, 2024 |
| CVE-2021-24151 | WP Editor < 1.2.7 - Authenticated SQL injection | HIGH | 7.2 | Jan 16, 2024 |
| CVE-2016-10885 | The wp-editor plugin before 1.2.6 for WordPress has CSRF. | HIGH | 8.8 | Aug 14, 2019 |
| CVE-2016-10886 | The wp-editor plugin before 1.2.6 for WordPress has incorrect permissions. | CRITICAL | 9.8 | Aug 14, 2019 |
Showing 1 to 7 of 7 CVEs