📦 Wp Extended

by Wpextended

🔍 What is Wp Extended?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2024-11916

HIGH CVSS 7.4 Jan 8, 2025

The WP Extended WordPress plugin has a missing capability check vulnerability that allows authenticated attackers with subscriber-level access or higher to import and activate arbitrary code snippets....

CVE-2024-8102

HIGH CVSS 8.8 Sep 4, 2024

This vulnerability in the WP Extended WordPress plugin allows authenticated attackers with Subscriber-level access or higher to modify arbitrary WordPress site options due to missing capability checks...

CVE-2024-37259

HIGH CVSS 7.1 Jul 22, 2024

This vulnerability allows attackers to inject malicious scripts into web pages generated by the WP Extended plugin, which could execute in users' browsers. It affects WordPress sites using the WP Exte...

CVE-2024-13554

MEDIUM CVSS 5.3 Feb 12, 2025

The WP Extended WordPress plugin has an authorization bypass vulnerability that allows unauthenticated attackers to reorder posts. This affects all WordPress sites using WP Extended plugin versions up...

CVE-2024-8123

MEDIUM CVSS 5.4 Sep 4, 2024

This vulnerability in the WP Extended WordPress plugin allows authenticated attackers with Contributor-level access or higher to duplicate posts created by other users, including administrators. Attac...

CVE-2024-8106

MEDIUM CVSS 6.5 Sep 4, 2024

This vulnerability in the WP Extended WordPress plugin allows authenticated attackers with Subscriber-level access or higher to extract sensitive user data including usernames, hashed passwords, and e...

CVE-2024-8119

MEDIUM CVSS 6.1 Sep 4, 2024

This vulnerability allows unauthenticated attackers to inject malicious scripts via the page parameter in the WP Extended WordPress plugin. When a user clicks a specially crafted link, the script exec...