Leyka <= 3.32.3 - Missing Authorization
medium
The Leyka plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 3.32.3. This makes it possible for authenticated attackers, with Subscriber-level access and above, to perform an unauthorized action.
- CVSS:
- 4.3
- Affected:
- up to 3.32.3
- Fix:
- No patched version reported
- Disclosed:
- Aug 19, 2026
CVE-2026-66677 on NVD →
Leyka [leyka] <= 3.31.9 (unfixed)
unknown
[en] Path Traversal vulnerability in VaultDweller Leyka allows PHP Local File Inclusion. This issue affects Leyka: from n/a through 3.31.9.
- Affected:
- up to 3.31.9
- Fix:
- No patched version reported
- Disclosed:
- Jul 4, 2025
CVE-2025-52805 on NVD →
Leyka <= 3.31.9 - Unauthenticated Local File Inclusion
high
The Leyka plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 3.31.9. This makes it possible for unauthenticated attackers to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obt...
- CVSS:
- 8.1
- Affected:
- up to 3.31.9
- Fix:
- No patched version reported
- Disclosed:
- Jul 1, 2025
CVE-2025-52805 on NVD →
Leyka <= 3.31.9 - Authenticated (Contributor+) Stored Cross-Site Scripting
medium
The Leyka plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 3.31.9 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will...
- CVSS:
- 6.4
- Affected:
- up to 3.31.9
- Fix:
- No patched version reported
- Disclosed:
- Jun 27, 2025
CVE-2025-53275 on NVD →
Leyka [leyka] <= 3.31.9 (unfixed)
unknown
[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in VaultDweller Leyka allows DOM-Based XSS. This issue affects Leyka: from n/a through 3.31.9.
- Affected:
- up to 3.31.9
- Fix:
- No patched version reported
- Disclosed:
- Jun 27, 2025
CVE-2025-53275 on NVD →
Leyka [leyka] < 3.31.9
unknown
[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in VaultDweller Leyka allows Stored XSS. This issue affects Leyka: from n/a through 3.31.8.
- Affected:
- up to 3.31.9
- Fixed in:
- 3.31.9
- Disclosed:
- Feb 16, 2025
CVE-2025-26766 on NVD →
Leyka <= 3.31.8 - Authenticated (Contributor+) Stored Cross-Site Scripting
medium
The Leyka plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 3.31.8 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will...
- CVSS:
- 6.4
- Affected:
- up to 3.31.8
- Fixed in:
- 3.31.9
- Disclosed:
- Feb 14, 2025
CVE-2025-26766 on NVD →
Leyka [leyka] < 3.31.7
unknown
[en] : Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Teplitsa of social technologies Leyka.This issue affects Leyka: from n/a through 3.31.6.
- Affected:
- up to 3.31.7
- Fixed in:
- 3.31.7
- Disclosed:
- Oct 16, 2024
CVE-2024-49252 on NVD →
Leyka <= 3.31.6 - Missing Authorization
medium
The Leyka plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the leyka_ajax_get_campaigns_list() function in all versions up to, and including, 3.31.6. This makes it possible for authenticated attackers, with subscriber-level access and above, to retrieve information...
- CVSS:
- 4.3
- Affected:
- up to 3.31.6
- Fixed in:
- 3.31.7
- Disclosed:
- Oct 14, 2024
CVE-2024-49252 on NVD →
Leyka [leyka] < 3.31.2
unknown
[en] Missing Authorization vulnerability in Teplitsa of social technologies Leyka.This issue affects Leyka: from n/a through 3.31.1.
- Affected:
- up to 3.31.2
- Fixed in:
- 3.31.2
- Disclosed:
- Jun 11, 2024
CVE-2024-35683 on NVD →
Leyka <= 3.31.1 - Missing Authorization
medium
The Leyka plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the sendCardCheck function in versions up to, and including, 3.31.1. This makes it possible for unauthenticated attackers to perform a card check.
- CVSS:
- 5.3
- Affected:
- up to 3.31.1
- Fixed in:
- 3.31.2
- Disclosed:
- Jun 6, 2024
CVE-2024-35683 on NVD →
Leyka [leyka] < 3.30.3
unknown
[en] Improper Privilege Management vulnerability in Teplitsa of social technologies Leyka allows Privilege Escalation.This issue affects Leyka: from n/a through 3.30.2.
- Affected:
- up to 3.30.3
- Fixed in:
- 3.30.3
- Disclosed:
- May 14, 2024
CVE-2023-33327 on NVD →
Leyka [leyka] < 3.30
unknown
[en] Cross-Site Request Forgery (CSRF) vulnerability in Teplitsa of social technologies Leyka plugin <= 3.29.2 versions.
- Affected:
- up to 3.30
- Fixed in:
- 3.30
- Disclosed:
- Nov 22, 2023
CVE-2023-27442 on NVD →
Leyka [leyka] < 3.30.3
unknown
[en] The Leyka WordPress plugin before 3.30.4 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)
- Affected:
- up to 3.30.3
- Fixed in:
- 3.30.3
- Disclosed:
- Sep 19, 2023
CVE-2023-2995 on NVD →
Leyka [leyka] < 3.30.7.1
unknown
[en] The Leyka plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 3.30.3 via the 'leyka_ajax_get_env_and_options' function. This can allow authenticated attackers with subscriber-level permissions or above to extract sensitive data including Sberbank API key and passw...
- Affected:
- up to 3.30.7.1
- Fixed in:
- 3.30.7.1
- Disclosed:
- Sep 13, 2023
CVE-2023-4917 on NVD →
Leyka <= 3.30.7 - Authenticated (Subscriber+) Sensitive Information Exposure
medium
The Leyka plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 3.30.7 via the 'leyka_ajax_get_env_and_options' function. This can allow authenticated attackers with subscriber-level permissions or above to extract sensitive data including Sberbank API key and password,...
- CVSS:
- 5.3
- Affected:
- up to 3.30.7
- Fixed in:
- 3.30.7.1
- Disclosed:
- Sep 12, 2023
CVE-2023-4917 on NVD →
Leyka [leyka] < 3.30.3
unknown
[en] Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Teplitsa of social technologies Leyka plugin <= 3.30.1 versions.
- Affected:
- up to 3.30.3
- Fixed in:
- 3.30.3
- Disclosed:
- Aug 30, 2023
CVE-2023-33325 on NVD →
Leyka <= 3.30.3 - Authenticated (Administrator+) Stored Cross-Site Scripting
medium
The Leyka plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versions up to, and including, 3.30.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary web...
- CVSS:
- 4.4
- Affected:
- up to 3.30.3
- Fixed in:
- 3.30.3
- Disclosed:
- Aug 23, 2023
CVE-2023-2995 on NVD →
Leyka [leyka] < 3.30.3
unknown
[en] Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Teplitsa of social technologies Leyka plugin <= 3.30.2 versions.
- Affected:
- up to 3.30.3
- Fixed in:
- 3.30.3
- Disclosed:
- Aug 10, 2023
CVE-2023-39314 on NVD →
Leyka <= 3.30.2 - Reflected Cross-Site Scripting
medium
The Leyka plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via several $_GET parameters in versions up to, and including, 3.30.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if t...
- CVSS:
- 6.1
- Affected:
- up to 3.30.2
- Fixed in:
- 3.30.3
- Disclosed:
- Aug 7, 2023
CVE-2023-39314 on NVD →
Leyka [leyka] < 3.30.3
unknown
[en] Unauth. Stored Cross-Site Scripting (XSS) vulnerability in Teplitsa of social technologies Leyka plugin <= 3.29.2 versions.
- Affected:
- up to 3.30.3
- Fixed in:
- 3.30.3
- Disclosed:
- Jun 21, 2023
CVE-2023-27450 on NVD →
Leyka <= 3.30.2 - Privilege Escalation via Admin Password Reset
critical
The Leyka plugin for WordPress is vulnerable to Privilege Escalation in versions up to, and including, 3.30.2. This allows donors users to gain administrator access by setting the passwords for an administrator account when initially setting their password.
- CVSS:
- 9.8
- Affected:
- up to 3.30.2
- Fixed in:
- 3.30.3
- Disclosed:
- May 22, 2023
CVE-2023-33327 on NVD →
Leyka <= 3.30.1 - Reflected Cross-Site Scripting
medium
The Leyka plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'stage' parameter in versions up to, and including, 3.30.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they...
- CVSS:
- 6.1
- Affected:
- up to 3.30.1
- Fixed in:
- 3.30.2
- Disclosed:
- May 22, 2023
CVE-2023-33325 on NVD →
Leyka <= 3.29.2 - Unauthenticated Stored Cross-Site Scripting
high
The Leyka plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 3.29.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an in...
- CVSS:
- 7.2
- Affected:
- up to 3.29.2
- Fixed in:
- 3.30
- Disclosed:
- Mar 3, 2023
CVE-2023-27450 on NVD →
Leyka <= 3.29.2 - Cross-Site Request Forgery
medium
The Leyka plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.29.2. This makes it possible for unauthenticated attackers to perform an unknown action granted they can trick a site administrator into performing an action such as clicking on a link. The impact of this vuln...
- CVSS:
- 5.4
- Affected:
- up to 3.29.2
- Fixed in:
- 3.30
- Disclosed:
- Mar 3, 2023
CVE-2023-27442 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database