cleantalk
Vulnerabilities and Security Researches

Vulnerabilities and security researches forhiweb-migration-simple hiweb-migration-simple

Direction: descending
Jun 04, 2026

hiWeb Migration Simple # CVE-2026-2425

CVE, Research URL

CVE-2026-2425

Date
Jun 02, 2026
Research Description
The hiWeb Migration Simple plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'new_domain' parameter in all versions up to, and including, 2.0.0.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick an administrator into performing an action such as clicking on a link.
Affected versions
max 2.0.0.1.
Status
vulnerable
Jun 07, 2024

hiWeb Migration Simple # CVE-2023-0769

CVE, Research URL

CVE-2023-0769

Date
Jan 16, 2024
Research Description
The hiWeb Migration Simple WordPress plugin through 2.0.0.1 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high-privilege users such as admins.
Affected versions
max 2.0.0.1.
Status
vulnerable