cleantalk
Vulnerabilities and Security Researches

Vulnerabilities and security researches forwplr-sync wplr-sync

Direction: ascending
Jun 07, 2024

Photo Engine (Media Organizer & Lightroom) # CVE-2023-38513

CVE, Research URL

CVE-2023-38513

Date
Dec 20, 2023
Research Description
Authorization Bypass Through User-Controlled Key vulnerability in Jordy Meow Photo Engine (Media Organizer & Lightroom).This issue affects Photo Engine (Media Organizer & Lightroom): from n/a through 6.2.5.
Affected versions
max 6.2.6.
Status
vulnerable
Aug 02, 2024

Photo Engine (Media Organizer & Lightroom) # CVE-2024-39660

CVE, Research URL

CVE-2024-39660

Date
Aug 02, 2024
Research Description
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Jordy Meow Photo Engine allows Stored XSS.This issue affects Photo Engine: from n/a through 6.3.1.
Affected versions
max 6.3.2.
Status
vulnerable
Aug 20, 2024

Photo Engine (Media Organizer & Lightroom) # CVE-2024-43332

CVE, Research URL

CVE-2024-43332

Date
Nov 01, 2024
Research Description
Missing Authorization vulnerability in Jordy Meow Photo Engine allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Photo Engine: from n/a through 6.4.0.
Affected versions
max 6.4.1.
Status
vulnerable
Aug 01, 2025

Photo Engine (Media Organizer & Lightroom) # CVE-2025-54672

CVE, Research URL

CVE-2025-54672

Date
Aug 14, 2025
Research Description
Cross-Site Request Forgery (CSRF) vulnerability in Jordy Meow Photo Engine allows Cross Site Request Forgery. This issue affects Photo Engine: from n/a through 6.4.3.
Affected versions
max 6.4.4.
Status
vulnerable
Mar 30, 2026

Photo Engine (Media Organizer & Lightroom) # CVE-2026-32524

CVE, Research URL

CVE-2026-32524

Date
Mar 25, 2026
Research Description
Unrestricted Upload of File with Dangerous Type vulnerability in Jordy Meow Photo Engine wplr-sync allows Upload a Web Shell to a Web Server.This issue affects Photo Engine: from n/a through <= 6.4.9.
Affected versions
max 6.4.9.
Status
vulnerable