plugin

Apartment Management Vulnerabilities

17 known security issues reported for the Apartment Management WordPress plugin. Most recent disclosed Apr 7, 2026.

2 critical 4 high 3 medium

Running Apartment Management on your site? Check whether your installed version is affected.

Scan your site free

WPAMS - Apartment Management System for wordpress < 49.5.3 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Content Deletion

medium

The WPAMS - Apartment Management System for wordpress plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to 49.5.3 (exclusive). This makes it possible for authenticated attackers, with Subscriber-level access and above, to delete arbitrary conten...

CVSS:
4.3
Affected:
up to 49.5.3
Fixed in:
49.5.3
Disclosed:
Apr 7, 2026

CVE-2026-39433 on NVD →

WPAMS [apartment-management] <= 44.0 (17-08-2023) (unfixed)

unknown

[en] Unrestricted Upload of File with Dangerous Type vulnerability in mojoomla WPAMS allows Upload a Web Shell to a Web Server.This issue affects WPAMS: from n/a through 44.0 (17-08-2023).

Affected:
up to 44.0 (17-08-2023)
Fix:
No patched version reported
Disclosed:
May 19, 2025

CVE-2025-39401 on NVD →

WPAMS [apartment-management] <= 44.0 (17-08-2023) (unfixed)

unknown

[en] Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in mojoomla WPAMS allows PHP Local File Inclusion.This issue affects WPAMS: from n/a through 44.0.

Affected:
up to 44.0 (17-08-2023)
Fix:
No patched version reported
Disclosed:
May 19, 2025

CVE-2025-39406 on NVD →

WPAMS [apartment-management] <= 44.0 (17-08-2023) (unfixed)

unknown

[en] Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in mojoomla WPAMS allows SQL Injection.This issue affects WPAMS: from n/a through 44.0 (17-08-2023).

Affected:
up to 44.0 (17-08-2023)
Fix:
No patched version reported
Disclosed:
May 19, 2025

CVE-2025-39403 on NVD →

WPAMS [apartment-management] <= 44.0 (17-08-2023) (unfixed)

unknown

[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in mojoomla WPAMS allows Reflected XSS.This issue affects WPAMS: from n/a through 44.0 (17-08-2023).

Affected:
up to 44.0 (17-08-2023)
Fix:
No patched version reported
Disclosed:
May 19, 2025

CVE-2025-39392 on NVD →

WPAMS [apartment-management] <= 44.0 (17-08-2023) (unfixed)

unknown

[en] Incorrect Privilege Assignment vulnerability in mojoomla WPAMS allows Privilege Escalation.This issue affects WPAMS: from n/a through 44.0 (17-08-2023).

Affected:
up to 44.0 (17-08-2023)
Fix:
No patched version reported
Disclosed:
May 19, 2025

CVE-2025-39405 on NVD →

WPAMS [apartment-management] <= 44.0 (17-08-2023) (unfixed)

unknown

[en] Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in mojoomla WPAMS allows SQL Injection.This issue affects WPAMS: from n/a through 44.0 (17-08-2023).

Affected:
up to 44.0 (17-08-2023)
Fix:
No patched version reported
Disclosed:
May 19, 2025

CVE-2025-39395 on NVD →

WPAMS [apartment-management] <= 44.0 (17-08-2023) (unfixed)

unknown

[en] Unrestricted Upload of File with Dangerous Type vulnerability in mojoomla WPAMS allows Upload a Web Shell to a Web Server.This issue affects WPAMS: from n/a through 44.0 (17-08-2023).

Affected:
up to 44.0 (17-08-2023)
Fix:
No patched version reported
Disclosed:
May 19, 2025

CVE-2025-39402 on NVD →

WPAMS <= 44.0 (17-08-2023) - Unauthenticated Arbitrary File Upload

critical

The WPAMS - Apartment Management System for wordpress plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in all versions up to, and including, 44.0 (17-08-2023). This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server whi...

CVSS:
9.8
Affected:
up to 44.0 (17-08-2023)
Fix:
No patched version reported
Disclosed:
Apr 17, 2025

CVE-2025-39401 on NVD →

WPAMS <= 44.0 - Unauthenticated Local File Inclusion

critical

The WPAMS plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 44.0. This makes it possible for unauthenticated attackers to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtai...

CVSS:
9.8
Affected:
up to 44.0 (17-08-2023)
Fix:
No patched version reported
Disclosed:
Apr 17, 2025

CVE-2025-39406 on NVD →

WPAMS <= 44.0 (17-08-2023) - Authenticated (Subscriber+) Arbitrary File Upload

high

The WPAMS - Apartment Management System for wordpress plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in all versions up to, and including, 44.0 (17-08-2023). This makes it possible for authenticated attackers, with Subscriber-level access and above, to upload arbitrary...

CVSS:
8.8
Affected:
up to 44.0 (17-08-2023)
Fix:
No patched version reported
Disclosed:
Apr 17, 2025

CVE-2025-39402 on NVD →

WPAMS <= 44.0 (17-08-2023) - Authenticated (Subscriber+) Privilege Escalation

high

The WPAMS - Apartment Management System for wordpress plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 44.0 (17-08-2023). This makes it possible for authenticated attackers, with Subscriber-level access and above, to elevate their privileges to that of an administrator.

CVSS:
8.8
Affected:
up to 44.0 (17-08-2023)
Fix:
No patched version reported
Disclosed:
Apr 17, 2025

CVE-2025-39405 on NVD →

WPAMS <= 44.0 (17-08-2023) - Unauthenticated SQL Injection

high

The WPAMS plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 44.0 (17-08-2023) due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queri...

CVSS:
7.5
Affected:
up to 44.0 (17-08-2023)
Fix:
No patched version reported
Disclosed:
Apr 17, 2025

CVE-2025-39395 on NVD →

WPAMS <= 44.0 (17-08-2023) - Authenticated (Subscriber+) SQL Injection

medium

The WPAMS plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 44.0 (17-08-2023) due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with subscriber-level access an...

CVSS:
6.5
Affected:
up to 44.0 (17-08-2023)
Fix:
No patched version reported
Disclosed:
Apr 17, 2025

CVE-2025-39403 on NVD →

WPAMS <= 44.0 (17-08-2023) - Unauthenticated Stored Cross-Site Scripting

medium

The WPAMS - Apartment Management System for wordpress plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 44.0 (17-08-2023) due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts...

CVSS:
6.1
Affected:
up to 44.0 (17-08-2023)
Fix:
No patched version reported
Disclosed:
Apr 17, 2025

CVE-2025-39392 on NVD →

WPAMS [apartment-management] <= 100

unknown

[en] Mojoomla WPAMS Apartment Management System for WordPress allows SQL Injection via the id parameter.

Affected:
up to 100
Fixed in:
100
Disclosed:
Sep 27, 2017

CVE-2017-14847 on NVD →

WPAMS - Apartment Management System for wordpress Theme < 17-07-2019 - SQL Injection

high

Mojoomla WPAMS Apartment Management System for WordPress allows SQL Injection via the id parameter.

CVSS:
8.8
Affected:
up to 17-07-2019
Fixed in:
17-07-2019
Disclosed:
Sep 26, 2017

CVE-2017-14847 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database