Vulnerabilities and security researches forflexi flexi
Direction: descendingApr 24, 2026
Flexi – Guest Submit # CVE-2025-9129
- CVE, Research URL
- Home page URL
- Application
- Date
- Oct 03, 2025
- Research Description
- The Flexi plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin for WordPress's flexi-form-tag shortcode in all versions up to, and including, 4.28 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
- Affected versions
-
max 4.28.
- Status
-
vulnerable
Apr 13, 2025
Flexi – Guest Submit # CVE-2025-32589
- CVE, Research URL
- Home page URL
- Application
- Date
- Apr 11, 2025
- Research Description
- Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in odude Flexi – Guest Submit allows PHP Local File Inclusion. This issue affects Flexi – Guest Submit: from n/a through 4.28.
- Affected versions
-
max 4.28.
- Status
-
vulnerable
Jun 07, 2024
Flexi – Guest Submit # CVE-2022-0449
- CVE, Research URL
- Home page URL
- Application
- Date
- Mar 14, 2022
- Research Description
- The Flexi WordPress plugin before 4.20 does not sanitise and escape various parameters before outputting them back in some pages such as the user dashboard, leading to a Reflected Cross-Site Scripting
- Affected versions
-
max 4.20.
- Status
-
vulnerable