VendorsWordPress Popular Posts Projectwordpress_popular_postsany version
Vulnerabilities

WordPress Popular Posts Project WordPress Popular Posts any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

5CVEs
CVE-2021-42362
WordPress Popular Posts <= 5.3.2 Authenticated Arbitrary File Upload
Published 2021-11-17 · Modified
8.81 PoCEPSS 0.798
CVE-2022-43468
External initialization of trusted variables or data stores vulnerability exists in WordPress Popular Posts 6.0.5 and earlier, therefore the vulnerable product accepts untrusted external inputs to update certain internal variables. As a result, the number of views for an article may be manipulated through a crafted input.
Published 2022-12-07 · Modified
7.5EPSS 0.009
CVE-2023-45607
WordPress WordPress Popular Posts Plugin <= 6.3.2 is vulnerable to Cross Site Scripting (XSS)
Published 2023-10-18 · Modified
6.5EPSS 0.003
CVE-2021-36872
WordPress Popular Posts plugin <= 5.3.3 - Authenticated Persistent Cross-Site Scripting (XSS) vulnerability
Published 2021-09-23 · Modified
5.5EPSS 0.006
CVE-2021-20746
Cross-site scripting vulnerability in WordPress Popular Posts 5.3.2 and earlier allows a remote authenticated attacker to inject an arbitrary script via unspecified vectors.
Published 2021-06-28 · Modified
5.4EPSS 0.014