CVE-2026-66440
- EPSS 0.19%
- Veröffentlicht 06.08.2026 14:27:49
- Zuletzt bearbeitet 12.08.2026 20:58:37
Unauthenticated Cross Site Scripting (XSS) in WPIDE – File Manager & Code Editor <= 3.5.7 versions.
CVE-2026-57766
- EPSS 0.14%
- Veröffentlicht 02.07.2026 11:16:07
- Zuletzt bearbeitet 02.07.2026 20:17:06
Unauthenticated Cross Site Request Forgery (CSRF) in WPIDE – File Manager & Code Editor <= 3.5.6 versions.
CVE-2024-9546
- EPSS 0.54%
- Veröffentlicht 15.10.2024 00:15:21
- Zuletzt bearbeitet 17.10.2024 13:34:27
The WPIDE – File Manager & Code Editor plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 3.4.9. This is due to the plugin utilizing the PHP-Parser library, which outputs parser rebuild command execution ...
CVE-2022-40217
- EPSS 0.88%
- Veröffentlicht 21.09.2022 20:15:11
- Zuletzt bearbeitet 20.02.2025 20:15:40
Authenticated (admin+) Arbitrary File Edit/Upload vulnerability in XplodedThemes WPide plugin <= 2.6 at WordPress.
CVE-2022-2261
- EPSS 1.17%
- Veröffentlicht 29.08.2022 18:15:09
- Zuletzt bearbeitet 21.11.2024 07:00:38
The WPIDE WordPress plugin before 3.0 does not sanitize and validate the filename parameter before using it in a require statement in the admin dashboard, leading to a Local File Inclusion issue.