Nelio A/B Testing – AB Tests and Heatmaps for Better Conversion Optimization <= 8.2.7 - Authenticated (Editor+) Remote Code Execution
high
The Nelio A/B Testing – AB Tests and Heatmaps for Better Conversion Optimization plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 8.2.7. This makes it possible for authenticated attackers, with Editor-level access and above, to execute code on the server.
- CVSS:
- 7.2
- Affected:
- up to 8.2.7
- Fixed in:
- 8.2.8
- Disclosed:
- Mar 23, 2026
CVE-2026-32573 on NVD →
Nelio AB Testing <= 8.2.8 - Unauthenticated Information Exposure
medium
The Nelio A/B Testing – AB Tests and Heatmaps for Better Conversion Optimization plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 8.2.8. This makes it possible for unauthenticated attackers to extract sensitive user or configuration data.
- CVSS:
- 5.3
- Affected:
- up to 8.2.8
- Fixed in:
- 8.3.0
- Disclosed:
- Mar 17, 2026
CVE-2026-40742 on NVD →
Nelio AB Testing <= 8.2.4 - Authenticated (Editor+) SQL Injection
medium
The Nelio AB Testing plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 8.2.4 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with editor-level access and abov...
- CVSS:
- 4.9
- Affected:
- up to 8.2.4
- Fixed in:
- 8.2.5
- Disclosed:
- Feb 19, 2026
CVE-2026-25378 on NVD →
Nelio A/B Testing – AB Tests and Heatmaps for Better Conversion Optimization [nelio-ab-testing] <= 8.2.4 (unfixed)
unknown
[en] Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Nelio Software Nelio AB Testing nelio-ab-testing allows Blind SQL Injection.This issue affects Nelio AB Testing: from n/a through <= 8.2.4.
- Affected:
- up to 8.2.4
- Fix:
- No patched version reported
- Disclosed:
- Feb 19, 2026
CVE-2026-25378 on NVD →
Nelio A/B Testing – AB Tests and Heatmaps for Better Conversion Optimization [nelio-ab-testing] <= 8.1.8 (unfixed)
unknown
[en] Improper Control of Generation of Code ('Code Injection') vulnerability in Nelio Software Nelio AB Testing nelio-ab-testing allows Code Injection.This issue affects Nelio AB Testing: from n/a through <= 8.1.8.
- Affected:
- up to 8.1.8
- Fix:
- No patched version reported
- Disclosed:
- Jan 22, 2026
CVE-2025-67944 on NVD →
Nelio AB Testing <= 8.1.8 - Authenticated (Editor+) Remote Code Execution
high
The Nelio A/B Testing – AB Tests and Heatmaps for Better Conversion Optimization plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 8.1.8. This makes it possible for authenticated attackers, with Editor-level access and above, to execute code on the server.
- CVSS:
- 7.2
- Affected:
- up to 8.1.8
- Fixed in:
- 8.2.0
- Disclosed:
- Jan 20, 2026
CVE-2025-67944 on NVD →
Nelio A/B Testing – AB Tests and Heatmaps for Better Conversion Optimization [nelio-ab-testing] < 4.5.0
unknown
[en] The nelio-ab-testing plugin before 4.5.0 for WordPress has filename=..%2f directory traversal.
- Affected:
- up to 4.5.0
- Fixed in:
- 4.5.0
- Disclosed:
- Sep 17, 2019
CVE-2016-10977 on NVD →
Nelio A/B Testing – AB Tests and Heatmaps for Better Conversion Optimization [nelio-ab-testing] < 4.5.9
unknown
[en] The nelio-ab-testing plugin before 4.5.9 for WordPress has SSRF in ajax/iesupport.php.
- Affected:
- up to 4.5.9
- Fixed in:
- 4.5.9
- Disclosed:
- Aug 22, 2019
CVE-2016-10926 on NVD →
Nelio A/B Testing – AB Tests and Heatmaps for Better Conversion Optimization [nelio-ab-testing] < 4.5.11
unknown
[en] The nelio-ab-testing plugin before 4.5.11 for WordPress has SSRF in ajax/iesupport.php.
- Affected:
- up to 4.5.11
- Fixed in:
- 4.5.11
- Disclosed:
- Aug 22, 2019
CVE-2016-10927 on NVD →
Nelio A/B Testing – AB Tests and Heatmaps for Better Conversion Optimization [nelio-ab-testing] < 4.6.4
unknown
[en] The nelio-ab-testing plugin before 4.6.4 for WordPress has CSRF in experiment forms.
- Affected:
- up to 4.6.4
- Fixed in:
- 4.6.4
- Disclosed:
- Aug 16, 2019
CVE-2017-18547 on NVD →
Nelio AB Testing < 4.6.4 - Cross-Site Request Forgery
high
The nelio-ab-testing plugin before 4.6.4 for WordPress has CSRF in experiment forms.
- CVSS:
- 8.8
- Affected:
- up to 4.6.4
- Fixed in:
- 4.6.4
- Disclosed:
- May 11, 2017
CVE-2017-18547 on NVD →
Nelio AB Testing < 4.5.11 - Server-Side Request Forgery
high
The nelio-ab-testing plugin before 4.5.11 for WordPress has SSRF in ajax/iesupport.php.
- CVSS:
- 7.2
- Affected:
- up to 4.5.11
- Fixed in:
- 4.5.11
- Disclosed:
- Dec 29, 2016
CVE-2016-10927 on NVD →
Nelio AB Testing < 4.5.9 - Server Side Request Forgery
high
The Nelio AB Testing plugin for WordPress is vulnerable to Server Side Request Forgery in versions up to, and including, 4.5.8 via the 'ajax/iesupport.php' file. This makes it possible for unauthenticated attackers to gain otherwise restricted information from the vulnerable service and potentially execute malicious co...
- CVSS:
- 8.3
- Affected:
- up to 4.5.8
- Fixed in:
- 4.5.9
- Disclosed:
- Dec 8, 2016
CVE-2016-10926 on NVD →
Nelio A/B Testing – AB Tests and Heatmaps for Better Conversion Optimization [nelio-ab-testing] < 4.5.9
unknown
This plugin is prone to a server side request forgery vulnerability. It allows attacker to collect various information about the server or even achieve remote code execution.
Update the plugin.
- Affected:
- up to 4.5.9
- Fixed in:
- 4.5.9
- Disclosed:
- Dec 8, 2016
Nelio A/B Testing – AB Tests and Heatmaps for Better Conversion Optimization [nelio-ab-testing] < 4.5.0
unknown
This vulnerability allows attackers to read the contents of files and expose sensitive data. If
the targeted file is used for a security mechanism, then the attacker is able to bypass that mechanism.
Update the plugin.
- Affected:
- up to 4.5.0
- Fixed in:
- 4.5.0
- Disclosed:
- May 11, 2016
Nelio AB Testing < 4.5.0 - Directory Traversal
medium
The Nelio AB Testing plugin for WordPress is vulnerable to Directory Traversal in versions up to, and including, 4.4.4 via the 'filename' parameter. This allows authenticated attackers to read the contents of arbitrary files on the server, which can contain sensitive information.
- CVSS:
- 6.5
- Affected:
- up to 4.4.4
- Fixed in:
- 4.5.0
- Disclosed:
- May 10, 2016
CVE-2016-10977 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database