Vulnerabilities and security researches forwp-editor wp-editor
Direction: ascendingJun 06, 2024
WP Editor # CVE-2016-10885
- CVE, Research URL
- Home page URL
- Application
- Date
- Aug 14, 2019
- Research Description
- The wp-editor plugin before 1.2.6 for WordPress has CSRF.
- Affected versions
-
Min -, max -.
- Status
-
vulnerable
WP Editor # CVE-2016-10886
- CVE, Research URL
- Home page URL
- Application
- Date
- Aug 14, 2019
- Research Description
- The wp-editor plugin before 1.2.6 for WordPress has incorrect permissions.
- Affected versions
-
Min -, max -.
- Status
-
vulnerable
WP Editor # CVE-2016-10877
- CVE, Research URL
- Home page URL
- Application
- Date
- Aug 12, 2019
- Research Description
- The wp-editor plugin before 1.2.6.3 for WordPress has multiple XSS issues.
- Affected versions
-
Min -, max -.
- Status
-
vulnerable
WP Editor # CVE-2024-24700
- CVE, Research URL
- Home page URL
- Application
- Date
- Mar 27, 2024
- Research Description
- Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Benjamin Rojas WP Editor allows Reflected XSS.This issue affects WP Editor: from n/a through 1.2.8.
- Affected versions
-
Min -, max -.
- Status
-
vulnerable
WP Editor # CVE-2024-25591
- CVE, Research URL
- Home page URL
- Application
- Date
- Mar 17, 2024
- Research Description
- Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Benjamin Rojas WP Editor.This issue affects WP Editor: from n/a through 1.2.7.
- Affected versions
-
Min -, max -.
- Status
-
vulnerable
Jun 10, 2024
WP Editor # CVE-2021-24151
- CVE, Research URL
- Home page URL
- Application
- Date
- Jan 16, 2024
- Research Description
- The WP Editor WordPress plugin before 1.2.7 did not sanitise or validate its setting fields leading to an authenticated (admin+) blind SQL injection issue via an arbitrary parameter when making a request to save the settings.
- Affected versions
-
Min -, max -.
- Status
-
vulnerable
Sep 14, 2024
WP Editor # CVE-2022-2446
- CVE, Research URL
- Home page URL
- Application
- Date
- Sep 13, 2024
- Research Description
- The WP Editor plugin for WordPress is vulnerable to deserialization of untrusted input via the 'current_theme_root' parameter in versions up to, and including 1.2.9. This makes it possible for authenticated attackers with administrative privileges to call files using a PHAR wrapper that will deserialize and call arbitrary PHP Objects that can be used to perform a variety of malicious actions granted a POP chain is also present. It also requires that the attacker is successful in uploading a file with the serialized payload.
- Affected versions
-
Min -, max -.
- Status
-
vulnerable
Apr 18, 2025
WP Editor # CVE-2025-3294
- CVE, Research URL
- Home page URL
- Application
- Date
- -
- Research Description
- WP Editor [wp-editor] < 1.2.9.2 CVE-2025-3294
- Affected versions
-
Min -, max -.
- Status
-
vulnerable
WP Editor # CVE-2025-3295
- CVE, Research URL
- Home page URL
- Application
- Date
- -
- Research Description
- WP Editor [wp-editor] < 1.2.9.2 CVE-2025-3295
- Affected versions
-
Min -, max -.
- Status
-
vulnerable