plugin

Droip Vulnerabilities

5 known security issues reported for the Droip WordPress plugin. Most recent disclosed Jul 24, 2025.

1 critical 2 high 2 medium

Running Droip on your site? Check whether your installed version is affected.

Scan your site free

Droip < 2.5.2 - Authenticated (Subscriber+) Arbitrary File Upload

high

The Droip plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the make_google_font_offline() function in all versions up to, and excluding, 2.5.2. This makes it possible for authenticated attackers, with Subscriber-level access and above, to upload arbitrary files on the...

CVSS:
8.8
Affected:
up to 2.5.2
Fixed in:
2.5.2
Disclosed:
Jul 24, 2025

CVE-2025-5831 on NVD →

Droip <= 2.2.6 - Missing Authorization to Authenticated (Subscriber+) Many Actions

high

The Droip plugin for WordPress is vulnerable to unauthorized modification and access of data due to a missing capability check on the droip_post_apis() function in all versions up to, and including, 2.2.6. This makes it possible for authenticated attackers, with Subscriber-level access and above, to perform many action...

CVSS:
8.8
Affected:
up to 2.2.6
Fixed in:
2.3.0
Disclosed:
Jul 24, 2025

CVE-2025-5835 on NVD →

Droip < 2.5.2 - Unauthenticated Arbitrary File Deletion

critical

The Droip plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in all versions up to 2.5.2 (exclusive). This makes it possible for unauthenticated attackers to delete arbitrary files on the server, which can easily lead to remote code execution when the right file is de...

CVSS:
9.1
Affected:
up to 2.5.2
Fixed in:
2.5.2
Disclosed:
Aug 26, 2024

CVE-2024-43955 on NVD →

Droip < 2.5.2 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Settings Change

medium

The Droip plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on a function in all versions up to, and ecluding, 2.5.2. This makes it possible for unauthenticated attackers to update the plugin's settings.

CVSS:
4.3
Affected:
up to 2.5.2
Fixed in:
2.5.2
Disclosed:
Aug 26, 2024

CVE-2024-43954 on NVD →

Droip < 2.5.2 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Settings Change

medium

The Droip plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on a function in all versions up to, and excluding, 2.5.2. This makes it possible for unauthenticated attackers to update the plugin's settings.

CVSS:
4.3
Affected:
up to 2.5.2
Fixed in:
2.5.2
Disclosed:
Aug 26, 2024

CVE-2024-43954 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database