simple-git < 3.15.0 - Remote Code Execution
critical
The package simple-git is vulnerable to Remote Code Execution in versions before 3.15.0 when the ext transport protocol is enabled. This makes the vulnerability exploitable using the clone method. WordPress plugins and themes may be using this package, however, may not be vulnerable to exploitation.
- CVSS:
- 9.8
- Affected:
- up to 1.0.5
- Fixed in:
- 1.0.6
- Disclosed:
- Dec 5, 2022
CVE-2022-25912 on NVD →
loader-utils (JS package) < 2.0.3 - Prototype Pollution
medium
The package loader-utils before 1.4.1, from 2.0.0 and before 2.0.3 is vulnerable to prototype pollution via the function parseQuery which could make injecting malicious web scripts possible in some cases.
- CVSS:
- 5.4
- Affected:
- up to 1.0.5
- Fixed in:
- 1.0.6
- Disclosed:
- Oct 12, 2022
CVE-2022-37601 on NVD →
loader-utils (JS package) < 3.2.1 - Regular Expression Denial of Service
low
The package loader-utils before 1.4.2, from 2.0.0 and before 2.0.4 as well as versions from 3.0.0 but below 3.2.1 are vulnerable to Regular Expression Denial of Service (ReDoS) via the interpolateName function due to insecure usage of regular expressions. Some WordPress plugins and themes use this dependency, however,...
- CVSS:
- 3.7
- Affected:
- up to 1.0.5
- Fixed in:
- 1.0.6
- Disclosed:
- Oct 11, 2022
CVE-2022-37599 on NVD →
loader-utils (JS package) < 3.2.1 - Regular Expression Denial of Service
low
The package loader-utils before 1.4.2, from 2.0.0 and before 2.0.4 as well as versions from 3.0.0 but below 3.2.1 are vulnerable to Regular Expression Denial of Service (ReDoS) via the resourcePath variable due to insecure usage of regular expressions. Some WordPress plugins and themes use this dependency, however, are...
- CVSS:
- 3.7
- Affected:
- up to 1.0.5
- Fixed in:
- 1.0.6
- Disclosed:
- Oct 11, 2022
CVE-2022-37603 on NVD →
guzzlehttp/psr7 <= 1.84 and 2.0.0-2.1.0 - Improper Input Validation
high
guzzlehttp/psr7 is a PSR-7 HTTP message library. Versions prior to 1.8.4 and 2.1.1 are vulnerable to improper header parsing. An attacker could sneak in a new line character and pass untrusted values. The issue is patched in 1.8.4 and 2.1.1. There are currently no known workarounds. Some WordPress plugins and themes us...
- CVSS:
- 7.5
- Affected:
- up to 1.0.4
- Fixed in:
- 1.0.5
- Disclosed:
- Jul 19, 2022
CVE-2022-24775 on NVD →
Insert Special Characters [insert-special-characters] < 1.0.5
unknown
[en] An exponential ReDoS (Regular Expression Denial of Service) can be triggered in the semver-regex npm package, when an attacker is able to supply arbitrary input to the test() method
- Affected:
- up to 1.0.5
- Fixed in:
- 1.0.5
- Disclosed:
- Jun 1, 2022
CVE-2021-43307 on NVD →
semver-regex <= 3.1.3 and 4.0.0-4.0.3 - Regular Expression Denial of Service (ReDoS)
high
An exponential ReDoS (Regular Expression Denial of Service) can be triggered in the semver-regex npm package, when an attacker is able to supply arbitrary input to the test() method. Some WordPress plugins and themes use this dependency though that doesn’t necessarily mean the plugin itself is vulnerable to exploitatio...
- CVSS:
- 7.5
- Affected:
- up to 1.0.4
- Fixed in:
- 1.0.5
- Disclosed:
- May 13, 2022
CVE-2021-43307 on NVD →
async <= 2.6.3 and 3-3.2.2 - Prototype Pollution
high
In Async before 2.6.4 and 3.x before 3.2.2, a malicious user can obtain privileges via the mapValues() method, aka lib/internal/iterator.js createObjectIterator prototype pollution. Some WordPress plugins and themes use this dependency though that doesn’t necessarily mean the plugin itself is vulnerable to exploitation...
- CVSS:
- 7.8
- Affected:
- up to 1.0.4
- Fixed in:
- 1.0.5
- Disclosed:
- Apr 7, 2022
CVE-2021-43138 on NVD →
Insert Special Characters [insert-special-characters] < 1.0.5
unknown
[en] In Async before 2.6.4 and 3.x before 3.2.2, a malicious user can obtain privileges via the mapValues() method, aka lib/internal/iterator.js createObjectIterator prototype pollution.
- Affected:
- up to 1.0.5
- Fixed in:
- 1.0.5
- Disclosed:
- Apr 6, 2022
CVE-2021-43138 on NVD →
Insert Special Characters [insert-special-characters] < 1.0.5
unknown
[en] guzzlehttp/psr7 is a PSR-7 HTTP message library. Versions prior to 1.8.4 and 2.1.1 are vulnerable to improper header parsing. An attacker could sneak in a new line character and pass untrusted values. The issue is patched in 1.8.4 and 2.1.1. There are currently no known workarounds.
- Affected:
- up to 1.0.5
- Fixed in:
- 1.0.5
- Disclosed:
- Mar 21, 2022
CVE-2022-24775 on NVD →
Minimist <= 1.2.5 - Prototype Pollution
critical
Minimist <=1.2.5 is vulnerable to Prototype Pollution via file index.js, function setKey() (lines 69-95). Fixed in 1.2.6. Some WordPress plugins and themes use this dependency though that doesn’t necessarily mean the plugin itself is vulnerable to exploitation.
- CVSS:
- 9.8
- Affected:
- up to 1.0.4
- Fixed in:
- 1.0.5
- Disclosed:
- Mar 18, 2022
Insert Special Characters [insert-special-characters] < 1.0.5
unknown
Minimist <=1.2.5 is vulnerable to Prototype Pollution via file index.js, function setKey() (lines 69-95). Fixed in 1.2.6. Some WordPress plugins and themes use this dependency though that doesn’t necessarily mean the plugin itself is vulnerable to exploitation.
- Affected:
- up to 1.0.5
- Fixed in:
- 1.0.5
- Disclosed:
- Mar 18, 2022
ansi-regex >=2.1.1 <3.0.1 >=4.0.0 <4.1.1 >=5.0.0 <5.0.1 >=6.0.0 <6.0.1 - Regular Expression Denial of Service (ReDoS)
high
ansi-regex is vulnerable to Inefficient Regular Expression Complexity. Some WordPress plugins and themes use this dependency though that doesn’t necessarily mean the plugin itself is vulnerable to exploitation.
- CVSS:
- 7.5
- Affected:
- up to 1.0.4
- Fixed in:
- 1.0.5
- Disclosed:
- Sep 9, 2021
Insert Special Characters [insert-special-characters] < 1.0.5
unknown
ansi-regex is vulnerable to Inefficient Regular Expression Complexity. Some WordPress plugins and themes use this dependency though that doesn’t necessarily mean the plugin itself is vulnerable to exploitation.
- Affected:
- up to 1.0.5
- Fixed in:
- 1.0.5
- Disclosed:
- Sep 9, 2021
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database