plugin

Nelio Ab Testing Vulnerabilities

16 known security issues reported for the Nelio Ab Testing WordPress plugin. Most recent disclosed Mar 23, 2026.

5 high 3 medium

Running Nelio Ab Testing on your site? Check whether your installed version is affected.

Scan your site free

Nelio A/B Testing – AB Tests and Heatmaps for Better Conversion Optimization <= 8.2.7 - Authenticated (Editor+) Remote Code Execution

high

The Nelio A/B Testing – AB Tests and Heatmaps for Better Conversion Optimization plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 8.2.7. This makes it possible for authenticated attackers, with Editor-level access and above, to execute code on the server.

CVSS:
7.2
Affected:
up to 8.2.7
Fixed in:
8.2.8
Disclosed:
Mar 23, 2026

CVE-2026-32573 on NVD →

Nelio AB Testing <= 8.2.8 - Unauthenticated Information Exposure

medium

The Nelio A/B Testing – AB Tests and Heatmaps for Better Conversion Optimization plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 8.2.8. This makes it possible for unauthenticated attackers to extract sensitive user or configuration data.

CVSS:
5.3
Affected:
up to 8.2.8
Fixed in:
8.3.0
Disclosed:
Mar 17, 2026

CVE-2026-40742 on NVD →

Nelio AB Testing <= 8.2.4 - Authenticated (Editor+) SQL Injection

medium

The Nelio AB Testing plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 8.2.4 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with editor-level access and abov...

CVSS:
4.9
Affected:
up to 8.2.4
Fixed in:
8.2.5
Disclosed:
Feb 19, 2026

CVE-2026-25378 on NVD →

Nelio A/B Testing – AB Tests and Heatmaps for Better Conversion Optimization [nelio-ab-testing] <= 8.2.4 (unfixed)

unknown

[en] Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Nelio Software Nelio AB Testing nelio-ab-testing allows Blind SQL Injection.This issue affects Nelio AB Testing: from n/a through <= 8.2.4.

Affected:
up to 8.2.4
Fix:
No patched version reported
Disclosed:
Feb 19, 2026

CVE-2026-25378 on NVD →

Nelio A/B Testing – AB Tests and Heatmaps for Better Conversion Optimization [nelio-ab-testing] <= 8.1.8 (unfixed)

unknown

[en] Improper Control of Generation of Code ('Code Injection') vulnerability in Nelio Software Nelio AB Testing nelio-ab-testing allows Code Injection.This issue affects Nelio AB Testing: from n/a through <= 8.1.8.

Affected:
up to 8.1.8
Fix:
No patched version reported
Disclosed:
Jan 22, 2026

CVE-2025-67944 on NVD →

Nelio AB Testing <= 8.1.8 - Authenticated (Editor+) Remote Code Execution

high

The Nelio A/B Testing – AB Tests and Heatmaps for Better Conversion Optimization plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 8.1.8. This makes it possible for authenticated attackers, with Editor-level access and above, to execute code on the server.

CVSS:
7.2
Affected:
up to 8.1.8
Fixed in:
8.2.0
Disclosed:
Jan 20, 2026

CVE-2025-67944 on NVD →

Nelio A/B Testing – AB Tests and Heatmaps for Better Conversion Optimization [nelio-ab-testing] < 4.5.0

unknown

[en] The nelio-ab-testing plugin before 4.5.0 for WordPress has filename=..%2f directory traversal.

Affected:
up to 4.5.0
Fixed in:
4.5.0
Disclosed:
Sep 17, 2019

CVE-2016-10977 on NVD →

Nelio A/B Testing – AB Tests and Heatmaps for Better Conversion Optimization [nelio-ab-testing] < 4.5.9

unknown

[en] The nelio-ab-testing plugin before 4.5.9 for WordPress has SSRF in ajax/iesupport.php.

Affected:
up to 4.5.9
Fixed in:
4.5.9
Disclosed:
Aug 22, 2019

CVE-2016-10926 on NVD →

Nelio A/B Testing – AB Tests and Heatmaps for Better Conversion Optimization [nelio-ab-testing] < 4.5.11

unknown

[en] The nelio-ab-testing plugin before 4.5.11 for WordPress has SSRF in ajax/iesupport.php.

Affected:
up to 4.5.11
Fixed in:
4.5.11
Disclosed:
Aug 22, 2019

CVE-2016-10927 on NVD →

Nelio A/B Testing – AB Tests and Heatmaps for Better Conversion Optimization [nelio-ab-testing] < 4.6.4

unknown

[en] The nelio-ab-testing plugin before 4.6.4 for WordPress has CSRF in experiment forms.

Affected:
up to 4.6.4
Fixed in:
4.6.4
Disclosed:
Aug 16, 2019

CVE-2017-18547 on NVD →

Nelio AB Testing < 4.6.4 - Cross-Site Request Forgery

high

The nelio-ab-testing plugin before 4.6.4 for WordPress has CSRF in experiment forms.

CVSS:
8.8
Affected:
up to 4.6.4
Fixed in:
4.6.4
Disclosed:
May 11, 2017

CVE-2017-18547 on NVD →

Nelio AB Testing < 4.5.11 - Server-Side Request Forgery

high

The nelio-ab-testing plugin before 4.5.11 for WordPress has SSRF in ajax/iesupport.php.

CVSS:
7.2
Affected:
up to 4.5.11
Fixed in:
4.5.11
Disclosed:
Dec 29, 2016

CVE-2016-10927 on NVD →

Nelio AB Testing < 4.5.9 - Server Side Request Forgery

high

The Nelio AB Testing plugin for WordPress is vulnerable to Server Side Request Forgery in versions up to, and including, 4.5.8 via the 'ajax/iesupport.php' file. This makes it possible for unauthenticated attackers to gain otherwise restricted information from the vulnerable service and potentially execute malicious co...

CVSS:
8.3
Affected:
up to 4.5.8
Fixed in:
4.5.9
Disclosed:
Dec 8, 2016

CVE-2016-10926 on NVD →

Nelio A/B Testing – AB Tests and Heatmaps for Better Conversion Optimization [nelio-ab-testing] < 4.5.9

unknown

This plugin is prone to a server side request forgery vulnerability. It allows attacker to collect various information about the server or even achieve remote code execution. Update the plugin.

Affected:
up to 4.5.9
Fixed in:
4.5.9
Disclosed:
Dec 8, 2016

Nelio A/B Testing – AB Tests and Heatmaps for Better Conversion Optimization [nelio-ab-testing] < 4.5.0

unknown

This vulnerability allows attackers to read the contents of files and expose sensitive data. If the targeted file is used for a security mechanism, then the attacker is able to bypass that mechanism. Update the plugin.

Affected:
up to 4.5.0
Fixed in:
4.5.0
Disclosed:
May 11, 2016

Nelio AB Testing < 4.5.0 - Directory Traversal

medium

The Nelio AB Testing plugin for WordPress is vulnerable to Directory Traversal in versions up to, and including, 4.4.4 via the 'filename' parameter. This allows authenticated attackers to read the contents of arbitrary files on the server, which can contain sensitive information.

CVSS:
6.5
Affected:
up to 4.4.4
Fixed in:
4.5.0
Disclosed:
May 10, 2016

CVE-2016-10977 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database