cleantalk
Vulnerabilities and Security Researches

Vulnerabilities and security researches forquttera-web-malware-scanner quttera-web-malware-scanner

Direction: descending
Aug 15, 2025

Quttera Web Malware Scanner # CVE-2025-8013

CVE, Research URL

CVE-2025-8013

Date
Aug 15, 2025
Research Description
The Quttera Web Malware Scanner plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 3.5.1.41 via the 'RunExternalScan' function. This makes it possible for authenticated attackers, with Administrator-level access and above, to make web requests to arbitrary locations originating from the web application and can be used to query and modify information from internal services.
Affected versions
Min -, max -.
Status
vulnerable
Jun 06, 2024

Quttera Web Malware Scanner # CVE-2023-6222

CVE, Research URL

CVE-2023-6222

Date
Dec 19, 2023
Research Description
IThe Quttera Web Malware Scanner WordPress plugin before 3.4.2.1 does not validate user input used in a path, which could allow users with an admin role to perform path traversal attacks
Affected versions
Min -, max -.
Status
vulnerable

Quttera Web Malware Scanner # CVE-2023-6065

CVE, Research URL

CVE-2023-6065

Date
Dec 19, 2023
Research Description
The Quttera Web Malware Scanner WordPress plugin before 3.4.2.1 doesn't restrict access to detailed scan logs, which allows a malicious actor to discover local paths and portions of the site's code
Affected versions
Min -, max -.
Status
vulnerable