VendorsSmartlogixwp-insertany version
Vulnerabilities

Smartlogix WP-Insert any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

2CVEs
CVE-2018-17573
The Wp-Insert plugin through 2.4.2 for WordPress allows upload of arbitrary PHP code because of the exposure and configuration of FCKeditor under fckeditor/editor/filemanager/browser/default/browser.html, fckeditor/editor/filemanager/connectors/test.html, and fckeditor/editor/filemanager/connectors/uploadtest.html.
Published 2018-09-28 · Modified
9.8EPSS 0.034
CVE-2023-25461
WordPress Wp-Insert Plugin <= 2.5.0 is vulnerable to Cross Site Scripting (XSS)
Published 2023-04-25 · Modified
5.9EPSS 0.004