Wordlift

Wordlift

4 vulnerabilities found.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.04%
  • Published 14.08.2025 18:21:52
  • Last modified 15.08.2025 13:12:51

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WordLift WordLift allows Stored XSS. This issue affects WordLift: from n/a through 3.54.5.

  • EPSS 0.05%
  • Published 06.06.2025 13:15:31
  • Last modified 06.06.2025 14:06:58

Missing Authorization vulnerability in WordLift WordLift allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects WordLift: from n/a through 3.54.4.

  • EPSS 0.11%
  • Published 07.01.2025 05:15:15
  • Last modified 07.01.2025 05:15:15

The WordLift – AI powered SEO – Schema plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the 'wl_config_plugin' AJAX action in all versions up to, and including, 3.54.0. This makes it possible for unauthen...

Exploit
  • EPSS 0.33%
  • Published 26.09.2022 13:15:10
  • Last modified 22.05.2025 14:15:59

The WordLift WordPress plugin before 3.37.2 does not sanitise and escape its settings, allowing high privilege users such as admin to perform cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.