CVE-2026-100506
- EPSS 0.37%
- Veröffentlicht 05.10.2026 19:00:11
- Zuletzt bearbeitet 06.10.2026 15:04:25
Deserialization of Untrusted Data vulnerability in WP Spell Check WP Spell Check wp-spell-check allows Object Injection.This issue affects WP Spell Check: from n/a through 12.1.
CVE-2025-25111
- EPSS 0.17%
- Veröffentlicht 07.02.2025 10:15:16
- Zuletzt bearbeitet 23.04.2026 15:25:37
Cross-Site Request Forgery (CSRF) vulnerability in WP Spell Check WP Spell Check wp-spell-check allows Cross Site Request Forgery.This issue affects WP Spell Check: from n/a through <= 9.21.
CVE-2024-22143
- EPSS 0.21%
- Veröffentlicht 31.01.2024 13:15:11
- Zuletzt bearbeitet 28.04.2026 19:23:11
Cross-Site Request Forgery (CSRF) vulnerability in WP Spell Check.This issue affects WP Spell Check: from n/a through 9.17.
CVE-2022-2658
- EPSS 0.47%
- Veröffentlicht 16.01.2023 16:15:10
- Zuletzt bearbeitet 21.11.2024 07:01:27
The WP Spell Check WordPress plugin before 9.13 does not escape ignored words, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in ...
CVE-2019-6027
- EPSS 0.68%
- Veröffentlicht 26.12.2019 16:15:12
- Zuletzt bearbeitet 21.11.2024 04:45:56
Cross-site request forgery (CSRF) vulnerability in WP Spell Check 7.1.9 and earlier allows remote attackers to hijack the authentication of administrators via unspecified vectors.