Vulnerabilities and security researches forworker worker
Direction: ascendingJun 06, 2024
ManageWP Worker # 789a6ab801477af9ad5fe7f355a0f14114bd6d5f
- CVE, Research URL
- Home page URL
- Application
- Date
- Feb 11, 2020
- Research Description
- ManageWP Worker [worker] < 4.9.3 Manage WP Worker <= 4.9.2 - Authentication Bypass The Manage WP Worker plugin for WordPress is vulnerable to authentication bypass in versions up to, and including 4.9.2, due to the use of global keys that every installation of Manage WP worker uses for signature verification. This makes it possible to specially craft a request that can be used to auto-login as any user on any WordPress site running the plugin.
- Affected versions
-
max 4.9.3.
- Status
-
vulnerable
Jan 29, 2025
ManageWP Worker # PSC-2024-64551
- PSC, Research URL
- Home page URL
- Application
- Date
- Aug 05, 2025
- Research Description
- The ManageWP Worker plugin, with over 1 million downloads, is a powerful tool for managing multiple WordPress websites from a single dashboard. It offers features such as automated backups, security monitoring, bulk updates, and website cloning. However, from a security standpoint, plugins with administrative control over multiple sites require strict scrutiny to ensure data integrity and prevent potential exploitation.
- Affected versions
-
Min 4.9.38, max 4.9.38.
- Status
-
SAFE & CERTIFIED
Apr 23, 2026
ManageWP Worker # CVE-2026-39463
- CVE, Research URL
- Home page URL
- Application
- Date
- Jun 16, 2026
- Research Description
- Unauthenticated Cross Site Scripting (XSS) in ManageWP Worker <= 4.9.31 versions.
- Affected versions
-
max 4.9.32.
- Status
-
vulnerable
May 15, 2026
ManageWP Worker # CVE-2026-3718
- CVE, Research URL
- Home page URL
- Application
- Date
- May 14, 2026
- Research Description
- The ManageWP Worker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'MWP-Key-Name' HTTP request header in all versions up to, and including, 4.9.31. This is due to insufficient input sanitization and output escaping of attacker-controlled header values. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever an administrator visits the plugin's connection management page with debug parameters.
- Affected versions
-
max 4.9.32.
- Status
-
vulnerable
Aug 25, 2026
ManageWP Worker # CVE-2026-18052
- CVE, Research URL
- Home page URL
- Application
- Date
- Aug 22, 2026
- Research Description
- The ManageWP Worker WordPress plugin before 4.9.37 does not bind the account being logged in to the signature which authorises the login, nor prevent an already used login link from being replayed, allowing attackers who obtain such a link to gain a session as any user on the site, including an administrator.
- Affected versions
-
max 4.9.37.
- Status
-
vulnerable