« Back to list

Wp-feedstats

Wp-feedstats Wordpress Plugin: vulnerabilities and CVEs

Wp-feedstats Wordpress Plugin has 7 published vulnerabilities, 6 of them in the last 12 months. 0 are rated critical and 0 are listed by CISA as actively exploited.

CVEs7
Last 12 months6
Critical0
Actively exploited0

All vulnerabilities in the catalogue →⭐ Follow this technology

Latest vulnerabilities

CVESeverityEPSSActive exploitationPublishedDescription
CVE-2026-84899Medium (6.8)0.43%—Sep 5, 2026
The VikWidgetsLoader WordPress plugin before 1.12.0 does not sanitise or escape a block attribute before outputting it inside an inline script, allowing users with the Contributor role to store arbitrary JavaScript that…
CVE-2025-15485High (8.2)0.20%—Sep 2, 2026
The Auto x LINE WordPress plugin through 1.0.0 does not have authorization checks in some of its REST endpoints, allowing unauthenticated users to call them and update the plugin settings, clear logs etc
CVE-2026-14333High (7.5)0.41%—Jul 31, 2026
The Demi WordPress plugin before 0.0.7 stores its full-site backup archives in a publicly accessible location under a predictable filename and without access protection, allowing unauthenticated attackers to download…
CVE-2026-14322Medium (5.3)0.30%—Jul 22, 2026
The Timetics WordPress plugin before 1.0.57 does not enforce a pending or unpaid status for new bookings created through a payment method other than its recognised gateways, allowing unauthenticated users to create…
CVE-2026-13156Medium (5.4)0.14%—Jul 20, 2026
The MailerSend WordPress plugin before 1.0.8 does not perform a nonce check on its configuration-delete action (it verifies the manage_options capability but ignores the nonce), so an attacker can trick a logged-in…
CVE-2026-8163High (8.8)0.43%—Jun 23, 2026
The Infility Global WordPress plugin before 2.15.19 does not properly sanitize and escape some parameters before using them in SQL statements, leading to a SQL Injection vulnerability exploitable by authenticated users…
CVE-2007-4104Medium (4.3)5.1%—Jul 31, 2007
Multiple cross-site scripting (XSS) vulnerabilities in the WP-FeedStats before 2.4 plugin for WordPress allow remote attackers to inject arbitrary web script or HTML via unspecified vectors, one of which involves an…