Autoshare for Twitter <= 2.3.1 - Missing Authorization
medium
The Autopost for X (formerly Autoshare for Twitter) plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 2.3.1. This makes it possible for authenticated attackers, with Subscriber-level access and above, to perform an unauthorize...
- CVSS:
- 4.3
- Affected:
- up to 2.3.1
- Fixed in:
- 2.3.2
- Disclosed:
- Jan 22, 2026
CVE-2026-25311 on NVD →
decode-uri-component <= 0.2.1 - Denial of Service
high
The decode-uri-component is vulnerable to Denial of Service due to improper input validation in versions up to, and including, 0.2.1 when certain search strings are parsed by the decodeUriComponent.
- CVSS:
- 7.5
- Affected:
- up to 1.2.1
- Fixed in:
- 1.3.0
- Disclosed:
- Jan 23, 2023
CVE-2022-38900 on NVD →
simple-git < 3.15.0 - Remote Code Execution
critical
The package simple-git is vulnerable to Remote Code Execution in versions before 3.15.0 when the ext transport protocol is enabled. This makes the vulnerability exploitable using the clone method. WordPress plugins and themes may be using this package, however, may not be vulnerable to exploitation.
- CVSS:
- 9.8
- Affected:
- up to 1.2.1
- Fixed in:
- 1.3.0
- Disclosed:
- Dec 5, 2022
CVE-2022-25912 on NVD →
Terser < 4.8.1 and 5.0.0-5.14.1 - Regular Expression Denial of Service
medium
The package terser before 4.8.1, from 5.0.0 and before 5.14.2 are vulnerable to Regular Expression Denial of Service (ReDoS) due to insecure usage of regular expressions. As this package is used in some WordPress plugins, this could result in the impacted plugins being vulnerable.
- CVSS:
- 5.3
- Affected:
- up to 1.1.2
- Fixed in:
- 1.2.0
- Disclosed:
- Jul 15, 2022
CVE-2022-25858 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database