Xplodedthemes

Wpide

5 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.19%
  • Veröffentlicht 06.08.2026 14:27:49
  • Zuletzt bearbeitet 12.08.2026 20:58:37

Unauthenticated Cross Site Scripting (XSS) in WPIDE – File Manager & Code Editor <= 3.5.7 versions.

  • EPSS 0.14%
  • Veröffentlicht 02.07.2026 11:16:07
  • Zuletzt bearbeitet 02.07.2026 20:17:06

Unauthenticated Cross Site Request Forgery (CSRF) in WPIDE – File Manager & Code Editor <= 3.5.6 versions.

  • EPSS 0.54%
  • Veröffentlicht 15.10.2024 00:15:21
  • Zuletzt bearbeitet 17.10.2024 13:34:27

The WPIDE – File Manager & Code Editor plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 3.4.9. This is due to the plugin utilizing the PHP-Parser library, which outputs parser rebuild command execution ...

  • EPSS 0.88%
  • Veröffentlicht 21.09.2022 20:15:11
  • Zuletzt bearbeitet 20.02.2025 20:15:40

Authenticated (admin+) Arbitrary File Edit/Upload vulnerability in XplodedThemes WPide plugin <= 2.6 at WordPress.

Exploit
  • EPSS 1.17%
  • Veröffentlicht 29.08.2022 18:15:09
  • Zuletzt bearbeitet 21.11.2024 07:00:38

The WPIDE WordPress plugin before 3.0 does not sanitize and validate the filename parameter before using it in a require statement in the admin dashboard, leading to a Local File Inclusion issue.