CVE-2025-67910
- EPSS 0.06%
- Veröffentlicht 08.01.2026 09:17:44
- Zuletzt bearbeitet 20.01.2026 15:19:29
Unrestricted Upload of File with Dangerous Type vulnerability in contentstudio Contentstudio contentstudio allows Upload a Web Shell to a Web Server.This issue affects Contentstudio: from n/a through <= 1.3.7.
CVE-2025-12181
- EPSS 0.35%
- Veröffentlicht 05.12.2025 05:31:24
- Zuletzt bearbeitet 08.12.2025 18:27:15
The ContentStudio plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the cstu_update_post() function in all versions up to, and including, 1.3.7. This makes it possible for authenticated attackers, wit...
CVE-2025-13144
- EPSS 0.02%
- Veröffentlicht 05.12.2025 05:31:20
- Zuletzt bearbeitet 08.12.2025 18:27:15
The ContentStudio plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.3.7. This is due to missing or insufficient nonce validation on the add_cstu_settings function. This makes it possible for unau...
CVE-2025-49990
- EPSS 0.04%
- Veröffentlicht 20.06.2025 15:15:25
- Zuletzt bearbeitet 23.06.2025 20:16:40
Missing Authorization vulnerability in contentstudio ContentStudio allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects ContentStudio: from n/a through 1.3.4.
CVE-2025-47692
- EPSS 0.17%
- Veröffentlicht 07.05.2025 14:20:57
- Zuletzt bearbeitet 08.05.2025 14:39:09
Missing Authorization vulnerability in contentstudio ContentStudio allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects ContentStudio: from n/a through 1.3.3.
CVE-2023-0556
- EPSS 1.65%
- Veröffentlicht 27.01.2023 22:15:09
- Zuletzt bearbeitet 21.11.2024 07:37:23
The ContentStudio plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on several functions in versions up to, and including, 1.2.5. This makes it possible for unauthenticated attackers to obtain the blog metad...
CVE-2023-0557
- EPSS 1.28%
- Veröffentlicht 27.01.2023 22:15:09
- Zuletzt bearbeitet 21.11.2024 07:37:23
The ContentStudio plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 1.2.5. This could allow unauthenticated attackers to obtain a nonce needed for the creation of posts.
CVE-2023-0558
- EPSS 1.57%
- Veröffentlicht 27.01.2023 22:15:09
- Zuletzt bearbeitet 21.11.2024 07:37:24
The ContentStudio plugin for WordPress is vulnerable to authorization bypass due to an unsecure token check that is susceptible to type juggling in versions up to, and including, 1.2.5. This makes it possible for unauthenticated attackers to execute ...