Vulnerabilities in wpmudev
55 resultsVexday analysis
O WPMU DEV apresenta 44 vulnerabilidades catalogadas, com 4 classificadas como críticas, mas nenhuma sob ataque ativo conhecido até o momento. A fraqueza dominante é CWE-862 (falta de autorização), padrão em plugins WordPress, e 5 novas vulnerabilidades foram publicadas nos últimos 90 dias, indicando descobertas recentes que requerem atenção aos patches.
CVE-2024-1794HIGHForminator <= 1.29.0 - Unauthenticated Stored Cross-Site Scripting via File UploadEPSS 0.5%CVE-2026-75528HIGHBroken Link Checker <= 2.4.13 - Unauthenticated Stored Cross-Site Scripting via Comment Author URL / Link LogEPSS 0.5%CVE-2026-12998MEDIUMForminator Forms <= 1.55.0.2 - Insecure Direct Object Reference to Unauthenticated Sensitive Information Disclosure via 'draft' ParameterEPSS 0.5%CVE-2024-10402HIGHForminator Forms – Contact Form, Payment Form & Custom Form Builder <= 1.35.1 - Missing Authorization to Authenticated (Contributor+) Form Update and CreationEPSS 0.5%CVE-2024-8981HIGHBroken Link Checker <= 2.4.0 - Reflected Cross-Site ScriptingEPSS 0.5%CVE-2026-18325HIGHForminator Forms <= 1.56.1 - Unauthenticated Stored Cross-Site Scripting via Forged Upload Record via Select FieldEPSS 0.5%CVE-2026-6214MEDIUMForminator Forms <= 1.53.0 - Missing Authorization to Authenticated (Subscriber+) Scheduled Form Submission Export via forminator_export_entries Action on wp_loaded HookEPSS 0.5%CVE-2026-18324HIGHForminator Forms <= 1.57.0.1 - Unauthenticated Stored Cross-Site Scripting via Rich-Text Textarea FieldEPSS 0.5%CVE-2024-6554MEDIUMBranda – White Label WordPress, Custom Login Page Customizer <= 3.4.18 - Unauthenticated Full Path DisclosureEPSS 0.5%CVE-2026-18323HIGHForminator Forms <= 1.57.0.2 - Unauthenticated Stored Cross-Site Scripting via Radio Field (Save and Continue Draft)EPSS 0.4%CVE-2026-76581CRITICALWPMU DEV Dashboard <= 5.0.1 - Authentication Bypass to Administrator via SSO HMAC Canonicalization ConfusionEPSS 0.4%CVE-2024-10579MEDIUMHustle – Email Marketing, Lead Generation, Optins, Popups <= 7.8.5 - Missing Authorization to Unpublished Form ExposureEPSS 0.4%CVE-2021-4417MEDIUMForminator – Contact Form, Payment Form & Custom Form Builder <= 1.13.4 - Cross-Site Request Forgery BypassEPSS 0.4%CVE-2026-6222MEDIUMForminator Forms <= 1.51.1 - Missing Authorization to Authenticated (Subscriber+) Sensitive Information Disclosure via 'forminator_action' ParameterEPSS 0.4%CVE-2024-10580MEDIUMHustle – Email Marketing, Lead Generation, Optins, Popups <= 7.8.5 - Missing Authorization to Unauthorized Form SubmissionEPSS 0.4%CVE-2024-9700MEDIUMForminator Forms – Contact Form, Payment Form & Custom Form Builder <= 1.36.0 - Insecure Direct Object Reference to Submission ManipulationEPSS 0.4%CVE-2024-6556MEDIUMSmartCrawl WordPress SEO checker, SEO analyzer, SEO optimizer <= 3.10.8 - Unauthenticated Full Path DisclosureEPSS 0.4%CVE-2026-2263MEDIUMHustle – Email Marketing, Lead Generation, Optins, Popups <= 7.8.10.2 - Missing Authorization to Unauthenticated Conversion Tracking Data ManipulationEPSS 0.4%CVE-2024-3053MEDIUMForminator – Contact Form, Payment Form & Custom Form Builder <= 1.29.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via forminator_form ShortcodeEPSS 0.4%CVE-2026-2729MEDIUMForminator – Contact Form, Payment Form & Custom Form Builder <= 1.52.0 - Missing Authorization to Unauthenticated Stripe PaymentIntent Reuse / Underpayment Bypass via 'paymentid' ParameterEPSS 0.4%