cleantalk
Vulnerabilities and Security Researches

Vulnerabilities and security researches forwp-webinarsystem wp-webinarsystem

Direction: ascending
Jun 07, 2024

WordPress Webinar Plugin – WebinarPress # CVE-2024-34818

CVE, Research URL

CVE-2024-34818

Date
May 14, 2024
Research Description
Cross-Site Request Forgery (CSRF) vulnerability in WebinarPress.This issue affects WebinarPress: from n/a through 1.33.17.
Affected versions
Min -, max -.
Status
vulnerable

WordPress Webinar Plugin – WebinarPress # CVE-2024-31256

CVE, Research URL

CVE-2024-31256

Date
Apr 07, 2024
Research Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WebinarPress allows Reflected XSS.This issue affects WebinarPress: from n/a through 1.33.9.
Affected versions
Min -, max -.
Status
vulnerable
Aug 20, 2024

WordPress Webinar Plugin – WebinarPress # CVE-2024-43339

CVE, Research URL

CVE-2024-43339

Date
Aug 27, 2024
Research Description
Cross-Site Request Forgery (CSRF) vulnerability in WebinarPress allows Cross-Site Scripting (XSS).This issue affects WebinarPress: from n/a through 1.33.20.
Affected versions
Min -, max -.
Status
vulnerable
Jan 09, 2025

WordPress Webinar Plugin – WebinarPress # CVE-2024-11271

CVE, Research URL

CVE-2024-11271

Date
Jan 08, 2025
Research Description
The WordPress Webinar Plugin – WebinarPress plugin for WordPress is vulnerable to modification of data due to a missing capability check on several functions in all versions up to, and including, 1.33.24. This makes it possible for authenticated attackers, with subscriber-level access and above, to modify webinars.
Affected versions
Min -, max -.
Status
vulnerable

WordPress Webinar Plugin – WebinarPress # CVE-2024-11270

CVE, Research URL

CVE-2024-11270

Date
Jan 08, 2025
Research Description
The WordPress Webinar Plugin – WebinarPress plugin for WordPress is vulnerable to arbitrary file creation due to a missing capability check on the 'sync-import-imgs' function and missing file type validation in all versions up to, and including, 1.33.24. This makes it possible for authenticated attackers, with subscriber-level access and above, to create arbitrary files that can lead to remote code execution.
Affected versions
Min -, max -.
Status
vulnerable
Apr 03, 2025

WordPress Webinar Plugin – WebinarPress # CVE-2025-31883

CVE, Research URL

CVE-2025-31883

Date
Apr 01, 2025
Research Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPWebinarSystem WebinarPress allows Stored XSS. This issue affects WebinarPress: from n/a through 1.33.27.
Affected versions
Min -, max -.
Status
vulnerable

WordPress Webinar Plugin – WebinarPress # CVE-2025-31882

CVE, Research URL

CVE-2025-31882

Date
Apr 01, 2025
Research Description
Missing Authorization vulnerability in WPWebinarSystem WebinarPress allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects WebinarPress: from n/a through 1.33.27.
Affected versions
Min -, max -.
Status
vulnerable