simple-git < 3.16.0 - Remote Code Execution
high
The package simple-git is vulnerable to Remote Code Execution in versions before 3.16.0 via the clone(), pull(), push() and listRemote() methods due to improper input sanitization. This is due to an incomplete fix of CVE-2022-25912. WordPress plugins and themes may be using this package, however, they may not be vulner...
- CVSS:
- 8.1
- Affected:
- up to 1.1.0
- Fixed in:
- 1.1.1
- Disclosed:
- Feb 23, 2023
CVE-2022-25860 on NVD →
json5 <= 1.0.1 and 2.0.0-2.2.1 - Prototype Pollution
high
The package json5 before 1.0.2 and between 2.0.0 and 2.2.1 inclusive is vulnerable to prototype pollution due to failure to restrict parsing of keys named `__proto__`. As this package is used in some WordPress plugins, this could result in the impacted plugins being vulnerable.
- CVSS:
- 8.8
- Affected:
- up to 1.0.3
- Fixed in:
- 1.1.0
- Disclosed:
- Dec 23, 2022
CVE-2022-46175 on NVD →
simple-git < 3.15.0 - Remote Code Execution
critical
The package simple-git is vulnerable to Remote Code Execution in versions before 3.15.0 when the ext transport protocol is enabled. This makes the vulnerability exploitable using the clone method. WordPress plugins and themes may be using this package, however, may not be vulnerable to exploitation.
- CVSS:
- 9.8
- Affected:
- up to 1.0.3
- Fixed in:
- 1.1.0
- Disclosed:
- Dec 5, 2022
CVE-2022-25912 on NVD →
loader-utils (JS package) < 2.0.3 - Prototype Pollution
medium
The package loader-utils before 1.4.1, from 2.0.0 and before 2.0.3 is vulnerable to prototype pollution via the function parseQuery which could make injecting malicious web scripts possible in some cases.
- CVSS:
- 5.4
- Affected:
- up to 1.0.3
- Fixed in:
- 1.1.0
- Disclosed:
- Oct 12, 2022
CVE-2022-37601 on NVD →
Terser < 4.8.1 and 5.0.0-5.14.1 - Regular Expression Denial of Service
medium
The package terser before 4.8.1, from 5.0.0 and before 5.14.2 are vulnerable to Regular Expression Denial of Service (ReDoS) due to insecure usage of regular expressions. As this package is used in some WordPress plugins, this could result in the impacted plugins being vulnerable.
- CVSS:
- 5.3
- Affected:
- up to 1.0.3
- Fixed in:
- 1.1.0
- Disclosed:
- Jul 15, 2022
CVE-2022-25858 on NVD →
markdown-it < 1.3.2 - Uncontrolled Resource Consumption
medium
The package markdown-it 1.3.2 is vulnerable to Uncontrolled Resource Consumption in cases where special patterns with length greater than 50 thousand characters are used. As this package is used in some WordPress plugins, this could result in the impacted plugins being vulnerable.
- CVSS:
- 5.3
- Affected:
- 1.0.3 – 1.0.3
- Fixed in:
- 1.1.0
- Disclosed:
- Jan 10, 2022
CVE-2022-21670 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database