Known Vulnerabilities for products from WordPlus
Listed below are 8 of the newest known vulnerabilities associated with the vendor "WordPlus".
These CVEs are retrieved based on exact matches on listed vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed vendor information are still displayed.
Data on known vulnerable products is also displayed based on information from known CPEs, each product links to its respective vulnerability page.
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2023-49168 json | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WordPlus Better Message... | Not Provided | 2023-12-14 | 2026-04-28 |
| CVE-2022-41609 json | Auth. (subscriber+) Server-Side Request Forgery (SSRF) vulnerability in Better Messages plugin 1.9.10.68 on WordPress. | 8.8 - HIGH | 2022-11-19 | 2022-11-21 |
| CVE-2022-40216 json | Auth. (subscriber+) Messaging Block Bypass vulnerability in Better Messages plugin <= 1.9.10.69 on WordPress. | Not Provided | 2022-11-18 | 2026-04-28 |
| CVE-2022-36389 json | Cross-Site Request Forgery (CSRF) vulnerability in WordPlus Better Messages plugin <= 1.9.9.148 at WordPress. | 8.8 - HIGH | 2022-08-23 | 2022-08-25 |
| CVE-2022-33142 json | Authenticated (subscriber+) Denial Of Service (DoS) vulnerability in WordPlus WordPress Better Messages plugin <= 1.9.10.57 a... | 6.5 - MEDIUM | 2022-08-23 | 2023-08-08 |
| CVE-2022-29454 json | Cross-Site Request Forgery (CSRF) vulnerability in WordPlus Better Messages plugin <= 1.9.9.148 at WordPress allows attackers... | 4.3 - MEDIUM | 2022-07-20 | 2022-07-26 |
| CVE-2021-24809 json | The BP Better Messages WordPress plugin before 1.9.9.41 does not check for CSRF in multiple of its AJAX actions: bp_better_me... | 8.8 - HIGH | 2021-11-01 | 2021-11-09 |
| CVE-2021-24808 json | The BP Better Messages WordPress plugin before 1.9.9.41 sanitise (with sanitize_text_field) but does not escape the 'subject'... | 6.1 - MEDIUM | 2021-11-01 | 2021-11-09 |