Miniorange
Miniorange Custom API FOR WP: vulnerabilidades y CVE
Miniorange Custom API FOR WP tiene 2 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 2 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE2
Últimos 12 meses0
Críticas2
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2025-54049 | Crítica (9.9) | 0.42% | — | 20 ago 2025 | Incorrect Privilege Assignment vulnerability in miniOrange Custom API for WP custom-api-for-wp allows Privilege Escalation.This issue affects Custom API for WP: from n/a through <= 4.2.2. |
| CVE-2025-54048 | Crítica (9.3) | 0.42% | — | 20 ago 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in miniOrange Custom API for WP custom-api-for-wp allows SQL Injection.This issue affects Custom API for WP: from n/a… |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.
Otros productos de Miniorange
Miniorange 2FA · 12Oauth Single Sign ON · 7Google Authenticator · 7Active Directory Integration / Ldap Integration · 6Saml SP Single Sign ON · 5Malware Scanner · 5OTP Verification With Firebase · 4Wordpress Social Login AND Register · 4Wordpress Social Login AND Register (discord, Google, Twitter, Linkedin) · 3Discord Integration · 3Page Restriction · 2Password Policy Manager · 2