plugin

Mwp Herd Effect Vulnerabilities

12 known security issues reported for the Mwp Herd Effect WordPress plugin. Most recent disclosed Jan 24, 2025.

1 high 5 medium

Running Mwp Herd Effect on your site? Check whether your installed version is affected.

Scan your site free

Herd Effects <= 6.2.1 - Cross-Site Request Forgery to Settings Update

medium

The Herd Effects plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 6.2.1. This is due to missing or incorrect nonce validation on a function. This makes it possible for unauthenticated attackers to update the plugin's settings via a forged request granted they can trick...

CVSS:
4.3
Affected:
up to 6.2.1
Fixed in:
6.2.2
Disclosed:
Jan 24, 2025

CVE-2025-24716 on NVD →

Social Proof Popups &amp; Real-Time Notifications – Herd Effects [mwp-herd-effect] < 6.2.2

unknown

[en] Cross-Site Request Forgery (CSRF) vulnerability in Wow-Company Herd Effects allows Cross Site Request Forgery. This issue affects Herd Effects: from n/a through 6.2.1.

Affected:
up to 6.2.2
Fixed in:
6.2.2
Disclosed:
Jan 24, 2025

CVE-2025-24716 on NVD →

Social Proof Popups &amp; Real-Time Notifications – Herd Effects [mwp-herd-effect] < 5.2.7

unknown

[en] The Herd Effects WordPress plugin before 5.2.7 does not have CSRF checks in some bulk actions, which could allow attackers to make logged in admins perform unwanted actions, such as deleting effects via CSRF attacks

Affected:
up to 5.2.7
Fixed in:
5.2.7
Disclosed:
May 2, 2024

CVE-2024-3478 on NVD →

Herd Effects – fake notifications and social proof plugin <= 5.2.6 - Cross-Site Request Forgery

medium

The Herd Effects – fake notifications and social proof plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 5.2.6. This is due to missing or incorrect nonce validation on the mwp-herd-effect page. This makes it possible for unauthenticated attackers to delete eff...

CVSS:
4.3
Affected:
up to 5.2.6
Fixed in:
5.2.7
Disclosed:
Apr 11, 2024

CVE-2024-3478 on NVD →

Social Proof Popups &amp; Real-Time Notifications – Herd Effects [mwp-herd-effect] < 5.2.4

unknown

[en] The Herd Effects WordPress plugin before 5.2.4 does not have CSRF when deleting its items, which could allow attackers to make logged in admins delete arbitrary effects via a CSRF attack

Affected:
up to 5.2.4
Fixed in:
5.2.4
Disclosed:
Sep 11, 2023

CVE-2023-4318 on NVD →

Social Proof Popups &amp; Real-Time Notifications – Herd Effects [mwp-herd-effect] < 5.2.3

unknown

[en] The Herd Effects WordPress plugin before 5.2.3 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

Affected:
up to 5.2.3
Fixed in:
5.2.3
Disclosed:
Sep 11, 2023

CVE-2023-4022 on NVD →

Herd Effects <= 5.2.2 - Authenticated (Administrator+) Stored Cross-Site Scripting

medium

The Herd Effects plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versions up to, and including, 5.2.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrar...

CVSS:
4.4
Affected:
up to 5.2.3
Fixed in:
5.2.3
Disclosed:
Aug 21, 2023

CVE-2023-4022 on NVD →

Herd Effects <= 5.2.3 - Cross-Site Request Forgery to Effect Deletion

medium

The Herd Effects for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 5.2.3. This is due to missing or incorrect nonce validation when deleting effects. This makes it possible for unauthenticated attackers to delete effects via a forged request granted they can trick a site admini...

CVSS:
4.3
Affected:
up to 5.2.3
Fixed in:
5.2.4
Disclosed:
Aug 21, 2023

CVE-2023-4318 on NVD →

Social Proof Popups &amp; Real-Time Notifications – Herd Effects [mwp-herd-effect] < 5.2.2

unknown

[en] The Float menu WordPress plugin before 5.0.2, Bubble Menu WordPress plugin before 3.0.4, Button Generator WordPress plugin before 2.3.5, Calculator Builder WordPress plugin before 1.5.1, Counter Box WordPress plugin before 1.2.2, Floating Button WordPress plugin before 5.3.1, Herd Effects WordPress plugin before 5...

Affected:
up to 5.2.2
Fixed in:
5.2.2
Disclosed:
Jun 12, 2023

CVE-2023-2362 on NVD →

Multiple Wow-Company Plugins (Various Versions) -- Reflected Cross-Site Scripting via 'page' parameter

medium

Several plugins by Wow-Company are vulnerable to Reflected Cross-Site Scripting via the ‘page’ parameter in various versions due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully tri...

CVSS:
6.1
Affected:
up to 5.2.1
Fixed in:
5.2.2
Disclosed:
May 22, 2023

CVE-2023-2362 on NVD →

Social Proof Popups &amp; Real-Time Notifications – Herd Effects [mwp-herd-effect] < 5.2.1

unknown

[en] Authenticated (admin or higher user role) Local File Inclusion (LFI) vulnerability in Wow-Company's Herd Effects plugin <= 5.2 at WordPress.

Affected:
up to 5.2.1
Fixed in:
5.2.1
Disclosed:
May 20, 2022

CVE-2022-29448 on NVD →

Herd Effects <= 5.2 - Local File Inclusion

high

Authenticated (admin or higher user role) Local File Inclusion (LFI) vulnerability in Wow-Company's Herd Effects plugin <= 5.2 at WordPress.

CVSS:
7.2
Affected:
up to 5.2
Fixed in:
5.2.1
Disclosed:
May 16, 2022

CVE-2022-29448 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database