Skip to main content

Vendor/product archive

wp-staging / wp_staging CVEs

Beta · best-effort

6 CVEs tagged to wp-staging / wp_staging0 Critical, 4 High, 2 Medium, 0 Low, 0 Unrated.

CVE-2024-5551

Published Jun 14, 2024

The WP STAGING Pro WordPress Backup Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 5.6.0. This is due to missing or…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2024-4469

Published May 31, 2024

The WP STAGING WordPress Backup Plugin WordPress plugin before 3.5.0 does not prevent users with the administrator role from pinging conducting SSRF attacks, which may be a probl…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2024-2309

Published Apr 17, 2024

The WP STAGING WordPress Backup Plugin WordPress plugin before 3.4.0, wp-staging-pro WordPress plugin before 5.4.0 does not sanitise and escape some of its settings, which could…

CVSS 4.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-7204

Published Jan 29, 2024

The WP STAGING WordPress Backup plugin before 3.2.0 allows access to cache files during the cloning process which provides

CVSS 7.5 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2023-6113

Published Jan 1, 2024

The WP STAGING WordPress Backup Plugin before 3.1.3 and WP STAGING Pro WordPress Backup Plugin before 5.1.3 do not prevent visitors from leaking key information about ongoing back…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2022-2737

Published Sep 16, 2022

The WP STAGING WordPress plugin before 2.9.18 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site…

CVSS 4.8 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-6 of 6 CVEsPage 1 of 1