plugin

Bulletproof Security Vulnerabilities

31 known security issues reported for the Bulletproof Security WordPress plugin. Most recent disclosed Jan 8, 2026.

2 high 10 medium

Running Bulletproof Security on your site? Check whether your installed version is affected.

Scan your site free

BulletProof Security [bulletproof-security] <= 6.9 (unfixed)

unknown

[en] Insertion of Sensitive Information Into Sent Data vulnerability in AITpro BulletProof Security bulletproof-security allows Retrieve Embedded Sensitive Data.This issue affects BulletProof Security: from n/a through <= 6.9.

Affected:
up to 6.9
Fix:
No patched version reported
Disclosed:
Jan 8, 2026

CVE-2025-67931 on NVD →

BulletProof Security <= 6.9 - Unauthenticated Sensitive Information Exposure

medium

The BulletProof Security plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 6.9. This makes it possible for unauthenticated attackers to extract sensitive user or configuration data.

CVSS:
5.3
Affected:
up to 6.9
Fixed in:
7.0
Disclosed:
Jan 6, 2026

CVE-2025-67931 on NVD →

BulletProof Security [bulletproof-security] < 6.1

unknown

[en] The BulletProof Security WordPress plugin before 6.1 does not sanitize and escape some of its CAPTCHA settings, which could allow high-privileged users to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed

Affected:
up to 6.1
Fixed in:
6.1
Disclosed:
May 16, 2022

CVE-2022-1265 on NVD →

BulletProof Security <= 6.0 - Stored Cross-Site Scripting

medium

The BulletProof Security WordPress plugin before 6.1 does not sanitize and escape some of its CAPTCHA settings, which could allow high-privileged users to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed

CVSS:
6.1
Affected:
up to 6.1
Fixed in:
6.1
Disclosed:
Apr 19, 2022

CVE-2022-1265 on NVD →

BulletProof Security [bulletproof-security] < 5.8

unknown

[en] The BulletProof Security WordPress plugin before 5.8 does not sanitise and escape some of its settings, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.

Affected:
up to 5.8
Fixed in:
5.8
Disclosed:
Mar 21, 2022

CVE-2022-0590 on NVD →

BulletProof Security <= 5.7 - Admin+ Stored Cross-Site Scripting

medium

The BulletProof Security WordPress plugin before 5.8 does not sanitise and escape some of its settings, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.

CVSS:
5.5
Affected:
up to 5.8
Fixed in:
5.8
Disclosed:
Feb 22, 2022

CVE-2022-0590 on NVD →

BulletProof Security [bulletproof-security] < 5.2

unknown

[en] The BulletProof Security WordPress plugin is vulnerable to sensitive information disclosure due to a file path disclosure in the publicly accessible ~/db_backup_log.txt file which grants attackers the full path of the site, in addition to the path of database backup files. This affects versions up to, and includin...

Affected:
up to 5.2
Fixed in:
5.2
Disclosed:
Sep 17, 2021

CVE-2021-39327 on NVD →

BulletProof Security <= 5.1 - Sensitive Information Disclosure

medium

The BulletProof Security WordPress plugin is vulnerable to sensitive information disclosure due to a file path disclosure in the publicly accessible ~/db_backup_log.txt file which grants attackers the full path of the site, in addition to the path of database backup files. This affects versions up to, and including, 5....

CVSS:
5.3
Affected:
up to 5.1
Fixed in:
5.2
Disclosed:
Sep 16, 2021

CVE-2021-39327 on NVD →

BulletProof Security [bulletproof-security] < 0.52.5

unknown

[en] In the admin/db-backup-security/db-backup-security.php page in the BulletProof Security plugin before .52.5 for WordPress, XSS is possible for remote authenticated administrators via the DBTablePrefix parameter.

Affected:
up to 0.52.5
Fixed in:
0.52.5
Disclosed:
Sep 12, 2017

CVE-2015-9230 on NVD →

BulletProof Security <= .53.3 - Authenticated Cross-Site Scripting

medium

The BulletProof Security plugin for WordPress is vulnerable to Cross-Site Scripting via the ‘user-agent-ignore’ parameter in versions up to, and including, .53.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers to inject arbitrary web scripts in pages that w...

CVSS:
6.4
Affected:
up to .53.4
Fixed in:
.53.4
Disclosed:
May 11, 2016

BulletProof Security [bulletproof-security] < 0.53.4

unknown

The BulletProof Security plugin for WordPress is vulnerable to Cross-Site Scripting via the ‘user-agent-ignore’ parameter in versions up to, and including, .53.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers to inject arbitrary web scripts in pages that w...

Affected:
up to 0.53.4
Fixed in:
0.53.4
Disclosed:
May 11, 2016

BulletProof Security [bulletproof-security] < 0.53.4

unknown

Because of this vulnerability, the attackers can inject arbitrary JavaScript or HTML code. Update the plugin.

Affected:
up to 0.53.4
Fixed in:
0.53.4
Disclosed:
May 11, 2016

BulletProof Security [bulletproof-security] < 0.53.3

unknown

Because of this vulnerability, the attackers can inject arbitrary JavaScript or HTML code. Update the plugin.

Affected:
up to 0.53.3
Fixed in:
0.53.3
Disclosed:
May 11, 2016

BulletProof Security <= .53.2 - Cross-Site Scripting

high

The BulletProof Security plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including, .53.2 due to insufficient input sanitization and output escaping on the bulletproof_security_options_email[bps_send_email_cc] and bulletproof_security_options_email[bps_send_email_bcc] parameters. This...

CVSS:
7.2
Affected:
up to .53.2
Fixed in:
.53.3
Disclosed:
Mar 17, 2016

BulletProof Security [bulletproof-security] < 0.53.3

unknown

The BulletProof Security plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including, .53.2 due to insufficient input sanitization and output escaping on the bulletproof_security_options_email[bps_send_email_cc] and bulletproof_security_options_email[bps_send_email_bcc] parameters. This...

Affected:
up to 0.53.3
Fixed in:
0.53.3
Disclosed:
Mar 17, 2016

BulletProof Security [bulletproof-security] < 0.52.5

unknown

Because of this vulnerability, the attackers can inject arbitrary JavaScript or HTML code. Update the plugin.

Affected:
up to 0.52.5
Fixed in:
0.52.5
Disclosed:
Oct 27, 2015

BulletProof Security [bulletproof-security] < 0.52.5

unknown

This plugin is prone to script insertion vulnerability. Update the plugin.

Affected:
up to 0.52.5
Fixed in:
0.52.5
Disclosed:
Sep 20, 2015

BulletProof Security [bulletproof-security] < 0.51.1

unknown

[en] Server-side request forgery (SSRF) vulnerability in admin/htaccess/bpsunlock.php in the BulletProof Security plugin before .51.1 for WordPress allows remote attackers to trigger outbound requests that authenticate to arbitrary databases via the dbhost parameter.

Affected:
up to 0.51.1
Fixed in:
0.51.1
Disclosed:
Dec 1, 2014

CVE-2014-8749 on NVD →

BulletProof Security [bulletproof-security] < 0.51.1

unknown

[en] Cross-site scripting (XSS) vulnerability in admin/htaccess/bpsunlock.php in the BulletProof Security plugin before .51.1 for WordPress allows remote attackers to inject arbitrary web script or HTML via the dbhost parameter.

Affected:
up to 0.51.1
Fixed in:
0.51.1
Disclosed:
Nov 6, 2014

CVE-2014-7958 on NVD →

BulletProof Security [bulletproof-security] < 0.51.1

unknown

[en] SQL injection vulnerability in admin/htaccess/bpsunlock.php in the BulletProof Security plugin before .51.1 for WordPress allows remote authenticated users to execute arbitrary SQL commands via the tableprefix parameter.

Affected:
up to 0.51.1
Fixed in:
0.51.1
Disclosed:
Nov 6, 2014

CVE-2014-7959 on NVD →

BulletProof Security < .51.1 - Cross-Site Scripting

medium

CVE-2014-7958: Cross-site scripting (XSS) vulnerability in admin/htaccess/bpsunlock.php in the BulletProof Security plugin before .51.1 for WordPress allows remote attackers to inject arbitrary web script or HTML via the dbhost parameter.

CVSS:
5.4
Affected:
up to .51.1
Fixed in:
.51.1
Disclosed:
Nov 5, 2014

CVE-2014-7958 on NVD →

BulletProof Security < .51.1 - Server-Side Request Forgery

medium

Server-side request forgery (SSRF) vulnerability in admin/htaccess/bpsunlock.php in the BulletProof Security plugin before .51.1 for WordPress allows remote attackers to trigger outbound requests that authenticate to arbitrary databases via the dbhost parameter.

CVSS:
4.3
Affected:
up to .51
Fixed in:
.51.1
Disclosed:
Nov 5, 2014

CVE-2014-8749 on NVD →

BulletProof Security < .51.1 - SQL Injection

high

SQL injection vulnerability in admin/htaccess/bpsunlock.php in the BulletProof Security plugin before .51.1 for WordPress allows remote authenticated users to execute arbitrary SQL commands via the tableprefix parameter.

CVSS:
8.8
Affected:
up to .51.1
Fixed in:
.51.1
Disclosed:
Oct 7, 2014

CVE-2014-7959 on NVD →

BulletProof Security < .52.5 - Cross-Site Scripting

medium

In the admin/db-backup-security/db-backup-security.php page in the BulletProof Security plugin before .52.5 for WordPress, XSS is possible for remote authenticated administrators via the DBTablePrefix parameter.

CVSS:
4.8
Affected:
up to .52.5
Fixed in:
.52.5
Disclosed:
Sep 30, 2014

CVE-2015-9230 on NVD →

BulletProof Security <= .48.9 - Cross-Site Scripting

medium

Multiple cross-site scripting (XSS) vulnerabilities in the security log in the BulletProof Security plugin before .49 for WordPress allow remote attackers to inject arbitrary web script or HTML via unspecified HTML header fields to (1) 400.php, (2) 403.php, or (3) 403.php.

CVSS:
6.1
Affected:
up to .48.9
Fixed in:
.49
Disclosed:
Aug 1, 2014

CVE-2013-3487 on NVD →

BulletProof Security [bulletproof-security] < 0.49

unknown

[en] Multiple cross-site scripting (XSS) vulnerabilities in the security log in the BulletProof Security plugin before .49 for WordPress allow remote attackers to inject arbitrary web script or HTML via unspecified HTML header fields to (1) 400.php, (2) 403.php, or (3) 403.php.

Affected:
up to 0.49
Fixed in:
0.49
Disclosed:
Mar 3, 2014

CVE-2013-3487 on NVD →

BulletProof Security [bulletproof-security] < 0.47.1

unknown

[en] Cross-site scripting (XSS) vulnerability in bulletproof-security/admin/options.php in the BulletProof Security plugin before .47.1 for WordPress allows remote attackers to inject arbitrary web script or HTML via the HTTP_ACCEPT_ENCODING header.

Affected:
up to 0.47.1
Fixed in:
0.47.1
Disclosed:
Aug 13, 2012

CVE-2012-4268 on NVD →

BulletProof Security < .47.1 - Reflected Cross-Site Scripting

medium

Cross-site scripting (XSS) vulnerability in bulletproof-security/admin/options.php in the BulletProof Security plugin before .47.1 for WordPress allows remote attackers to inject arbitrary web script or HTML via the HTTP_ACCEPT_ENCODING header.

CVSS:
6.1
Affected:
up to .47.1
Fixed in:
.47.1
Disclosed:
May 11, 2012

CVE-2012-4268 on NVD →

BulletProof Security [bulletproof-security] < 0.53.4

unknown

The BulletProof Security WordPress plugin was affected by a Multiple XSS Vulnerabilities security vulnerability.

Affected:
up to 0.53.4
Fixed in:
0.53.4

BulletProof Security [bulletproof-security] < 0.53.3

unknown

The BulletProof Security WordPress plugin was affected by a Multiple Cross Site Scripting Vulnerabilities security vulnerability.

Affected:
up to 0.53.3
Fixed in:
0.53.3

BulletProof Security [bulletproof-security] < 0.52.5

unknown

The BulletProof Security WordPress plugin was affected by an Authenticated Cross-Site Scripting (XSS) security vulnerability.

Affected:
up to 0.52.5
Fixed in:
0.52.5

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database