cleantalk
Vulnerabilities and Security Researches

Vulnerabilities and security researches forappsero-helper appsero-helper

Direction: descending
Apr 26, 2025

Appsero Helper # CVE-2025-39377

CVE, Research URL

CVE-2025-39377

Application

Appsero Helper

Date
Apr 24, 2025
Research Description
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in weDevs Appsero Helper allows SQL Injection. This issue affects Appsero Helper: from n/a through 1.3.4.
Affected versions
Min -, max -.
Status
vulnerable
Mar 12, 2025

Appsero Helper # CVE-2024-13436

CVE, Research URL

CVE-2024-13436

Application

Appsero Helper

Date
Mar 11, 2025
Research Description
The Appsero Helper plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.3.2. This is due to missing or incorrect nonce validation on the 'appsero_helper' page. This makes it possible for unauthenticated attackers to update settings and inject malicious web scripts via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
Affected versions
Min -, max -.
Status
vulnerable