Droip < 2.5.2 - Authenticated (Subscriber+) Arbitrary File Upload
high
The Droip plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the make_google_font_offline() function in all versions up to, and excluding, 2.5.2. This makes it possible for authenticated attackers, with Subscriber-level access and above, to upload arbitrary files on the...
- CVSS:
- 8.8
- Affected:
- up to 2.5.2
- Fixed in:
- 2.5.2
- Disclosed:
- Jul 24, 2025
CVE-2025-5831 on NVD →
Droip <= 2.2.6 - Missing Authorization to Authenticated (Subscriber+) Many Actions
high
The Droip plugin for WordPress is vulnerable to unauthorized modification and access of data due to a missing capability check on the droip_post_apis() function in all versions up to, and including, 2.2.6. This makes it possible for authenticated attackers, with Subscriber-level access and above, to perform many action...
- CVSS:
- 8.8
- Affected:
- up to 2.2.6
- Fixed in:
- 2.3.0
- Disclosed:
- Jul 24, 2025
CVE-2025-5835 on NVD →
Droip < 2.5.2 - Unauthenticated Arbitrary File Deletion
critical
The Droip plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in all versions up to 2.5.2 (exclusive). This makes it possible for unauthenticated attackers to delete arbitrary files on the server, which can easily lead to remote code execution when the right file is de...
- CVSS:
- 9.1
- Affected:
- up to 2.5.2
- Fixed in:
- 2.5.2
- Disclosed:
- Aug 26, 2024
CVE-2024-43955 on NVD →
Droip < 2.5.2 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Settings Change
medium
The Droip plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on a function in all versions up to, and ecluding, 2.5.2. This makes it possible for unauthenticated attackers to update the plugin's settings.
- CVSS:
- 4.3
- Affected:
- up to 2.5.2
- Fixed in:
- 2.5.2
- Disclosed:
- Aug 26, 2024
CVE-2024-43954 on NVD →
Droip < 2.5.2 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Settings Change
medium
The Droip plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on a function in all versions up to, and excluding, 2.5.2. This makes it possible for unauthenticated attackers to update the plugin's settings.
- CVSS:
- 4.3
- Affected:
- up to 2.5.2
- Fixed in:
- 2.5.2
- Disclosed:
- Aug 26, 2024
CVE-2024-43954 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database