Wp-staging
Wp-staging WP Staging: vulnerabilidades y CVE
Wp-staging WP Staging tiene 8 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 1 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE8
Últimos 12 meses0
Críticas1
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2024-5551 | Alta (8.8) | 0.28% | — | 14 jun 2024 | The WP STAGING Pro WordPress Backup Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 5.6.0. This is due to missing or incorrect nonce validation on the 'sub'… |
| CVE-2024-4469 | Alta (7.5) | 0.59% | — | 31 may 2024 | The WP STAGING WordPress Backup Plugin WordPress plugin before 3.5.0 does not prevent users with the administrator role from pinging conducting SSRF attacks, which may be a problem in multisite configurations. |
| CVE-2024-3412 | Crítica (9.1) | 0.79% | — | 29 may 2024 | The WP STAGING WordPress Backup Plugin – Migration Backup Restore plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the wpstg_processing AJAX action in all versions up… |
| CVE-2024-3682 | Media (5.3) | 0.58% | — | 26 abr 2024 | The WP STAGING and WP STAGING Pro plugins for WordPress are vulnerable to Sensitive Information Exposure in versions up to, and including, 3.4.3, and versions up to, and including, 5.4.3, respectively, via the… |
| CVE-2024-2309 | Media (4.8) | 0.42% | — | 17 abr 2024 | The WP STAGING WordPress Backup Plugin WordPress plugin before 3.4.0, wp-staging-pro WordPress plugin before 5.4.0 does not sanitise and escape some of its settings, which could allow high privilege users such as admin… |
| CVE-2023-7204 | Alta (7.5) | 0.64% | — | 29 ene 2024 | The WP STAGING WordPress Backup plugin before 3.2.0 allows access to cache files during the cloning process which provides |
| CVE-2023-6113 | Alta (7.5) | 0.78% | — | 1 ene 2024 | The WP STAGING WordPress Backup Plugin before 3.1.3 and WP STAGING Pro WordPress Backup Plugin before 5.1.3 do not prevent visitors from leaking key information about ongoing backups processes, allowing unauthenticated… |
| CVE-2022-2737 | Media (4.8) | 0.66% | — | 16 sept 2022 | The WP STAGING WordPress plugin before 2.9.18 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the… |