cleantalk
Vulnerabilities and Security Researches

Vulnerabilities and security researches forstafflist stafflist

Direction: descending
Dec 11, 2025

StaffList # CVE-2025-12185

CVE, Research URL

CVE-2025-12185

Application

StaffList

Date
Nov 27, 2025
Research Description
The StaffList plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 3.2.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.
Affected versions
max 3.2.7.
Status
vulnerable
Apr 06, 2025

StaffList # CVE-2025-32232

CVE, Research URL

CVE-2025-32232

Application

StaffList

Date
Apr 04, 2025
Research Description
Missing Authorization vulnerability in ERA404 StaffList allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects StaffList: from n/a through 3.2.6.
Affected versions
max 3.2.6.
Status
vulnerable

StaffList # CVE-2025-32255

CVE, Research URL

CVE-2025-32255

Application

StaffList

Date
Apr 04, 2025
Research Description
Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in ERA404 StaffList allows Retrieve Embedded Sensitive Data. This issue affects StaffList: from n/a through 3.2.6.
Affected versions
max 3.2.6.
Status
vulnerable
Feb 12, 2025

StaffList # CVE-2024-13749

CVE, Research URL

CVE-2024-13749

Application

StaffList

Date
Feb 12, 2025
Research Description
The StaffList plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.2.3. This is due to missing or incorrect nonce validation on the 'stafflist' page. This makes it possible for unauthenticated attackers to update settings and inject malicious web scripts via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
Affected versions
max 3.2.4.
Status
vulnerable
Jun 07, 2024

StaffList # CVE-2022-1556

CVE, Research URL

CVE-2022-1556

Application

StaffList

Date
May 30, 2022
Research Description
The StaffList WordPress plugin before 3.1.5 does not properly sanitise and escape a parameter before using it in a SQL statement when searching for Staff in the admin dashboard, leading to an SQL Injection
Affected versions
max 3.1.5.
Status
vulnerable

StaffList # 9cc3fcd165efb3b7ed4fa445dd8be2e97b715325

Application

StaffList

Date
May 04, 2022
Research Description
StaffList [stafflist] <= 3.1.5 WordPress StaffList plugin <= 3.1.5 - Arbitrary Staff Deletion via Cross-Site Request Forgery (CSRF) vulnerability Arbitrary Staff Deletion via Cross-Site Request Forgery (CSRF) vulnerability was discovered by Hassan Khan Yusufzai in the WordPress StaffList plugin (versions <= 3.1.5).
Affected versions
max 3.1.5.
Status
vulnerable