Vulnerabilities and security researches forfile-provider file-provider
Direction: descendingJun 15, 2025
File Provider # CVE-2025-4578
- CVE, Research URL
- Home page URL
- Application
- Date
- Jun 04, 2025
- Research Description
- The File Provider WordPress plugin through 1.2.3 does not properly sanitise and escape a parameter before using it in a SQL statement via an AJAX action available to unauthenticated users, leading to a SQL injection
- Affected versions
-
Min -, max -.
- Status
-
vulnerable
File Provider # CVE-2025-4580
- CVE, Research URL
- Home page URL
- Application
- Date
- Jun 04, 2025
- Research Description
- The File Provider WordPress plugin through 1.2.3 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack
- Affected versions
-
Min -, max -.
- Status
-
vulnerable