Community by PeepSo – Download from PeepSo.com <= 9.0.5.2 - Authenticated (Subscriber+) SQL Injection
medium
The Community by PeepSo – Download from PeepSo.com plugin for WordPress is vulnerable to SQL Injection in all versions up to, and including, 9.0.5.2. This is due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated...
- CVSS:
- 6.5
- Affected:
- up to 9.0.5.2
- Fixed in:
- 9.0.5.3
- Disclosed:
- Aug 19, 2026
CVE-2026-66668 on NVD →
Community by PeepSo – Social Network, Membership, Registration, User Profiles [peepso-core] <= 6.4.6.2 (unfixed + closed)
unknown
[en] The Community by PeepSo – Download from PeepSo.com plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘filter’ parameter in all versions up to, and including, 7.0.3.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject...
- Affected:
- up to 6.4.6.2
- Fix:
- No patched version reported
- Disclosed:
- Nov 21, 2024
CVE-2024-11447 on NVD →
Community by PeepSo – Social Network, Membership, Registration, User Profiles, Premium – Mobile App <=7.0.3.0 - Reflected Cross-Site Scripting
medium
The Community by PeepSo – Download from PeepSo.com plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘filter’ parameter in all versions up to, and including, 7.0.3.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbi...
- CVSS:
- 6.1
- Affected:
- up to 7.0.3.0
- Fixed in:
- 7.0.4.0
- Disclosed:
- Nov 20, 2024
CVE-2024-11447 on NVD →
Community by PeepSo – Social Network, Membership, Registration, User Profiles [peepso-core] < 6.4.6.2 (closed)
unknown
[en] The Community by PeepSo – Social Network, Membership, Registration, User Profiles, Premium – Mobile App plugin for WordPress is vulnerable to Stored Cross-Site Scripting via URLs in posts, comments, and profiles when Markdown support is enabled in all versions up to, and including, 6.4.6.1 due to insufficient inpu...
- Affected:
- up to 6.4.6.2
- Fixed in:
- 6.4.6.2
- Disclosed:
- Oct 16, 2024
CVE-2024-9873 on NVD →
Community by PeepSo <= 6.4.6.1 - Authenticated (Subscriber+) Stored Cross-Site Scripting
medium
The Community by PeepSo – Social Network, Membership, Registration, User Profiles, Premium – Mobile App plugin for WordPress is vulnerable to Stored Cross-Site Scripting via URLs in posts, comments, and profiles when Markdown support is enabled in all versions up to, and including, 6.4.6.1 due to insufficient input san...
- CVSS:
- 5.4
- Affected:
- up to 6.4.6.1
- Fixed in:
- 6.4.6.2
- Disclosed:
- Oct 15, 2024
CVE-2024-9873 on NVD →
Community by PeepSo – Social Network, Membership, Registration, User Profiles [peepso-core] < 6.4.6.1 (closed)
unknown
[en] The Community by PeepSo – Social Network, Membership, Registration, User Profiles plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 6.4.6.0. This is due to the plugin displaying errors and allowing direct access to the sse.php file. This makes it possible for unauthen...
- Affected:
- up to 6.4.6.1
- Fixed in:
- 6.4.6.1
- Disclosed:
- Sep 25, 2024
CVE-2024-7426 on NVD →
Community by PeepSo – Social Network, Membership, Registration, User Profiles <= 6.4.6.0 - Unauthenticated Full Path Disclosure
medium
The Community by PeepSo – Social Network, Membership, Registration, User Profiles plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 6.4.6.0. This is due to the plugin displaying errors and allowing direct access to the sse.php file. This makes it possible for unauthenticat...
- CVSS:
- 5.3
- Affected:
- up to 6.4.6.0
- Fixed in:
- 6.4.6.1
- Disclosed:
- Sep 24, 2024
CVE-2024-7426 on NVD →
Community by PeepSo – Social Network, Membership, Registration, User Profiles [peepso-core] < 6.4.6.0 (closed)
unknown
[en] The Community by PeepSo – Social Network, Membership, Registration, User Profiles plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 6.4.5.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with admi...
- Affected:
- up to 6.4.6.0
- Fixed in:
- 6.4.6.0
- Disclosed:
- Sep 10, 2024
CVE-2024-7655 on NVD →
Community by PeepSo – Social Network, Membership, Registration, User Profiles [peepso-core] < 6.4.6.0 (closed)
unknown
[en] The Community by PeepSo – Social Network, Membership, Registration, User Profiles plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘content’ parameter in all versions up to, and including, 6.4.5.0 due to insufficient input sanitization and output escaping. This makes it possible for authen...
- Affected:
- up to 6.4.6.0
- Fixed in:
- 6.4.6.0
- Disclosed:
- Sep 10, 2024
CVE-2024-7618 on NVD →
Community by PeepSo – Social Network, Membership, Registration, User Profiles <= 6.4.5.0 - Authenticated (Administrator+) Stored Cross-Site Scripting via content Parameter
medium
The Community by PeepSo – Social Network, Membership, Registration, User Profiles plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘content’ parameter in all versions up to, and including, 6.4.5.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticat...
- CVSS:
- 4.4
- Affected:
- up to 6.4.5.0
- Fixed in:
- 6.4.6.0
- Disclosed:
- Sep 9, 2024
CVE-2024-7618 on NVD →
Community by PeepSo – Social Network, Membership, Registration, User Profiles <= 6.4.5.0 - Authenticated (Administrator+) Stored Cross-Site Scripting
medium
The Community by PeepSo – Social Network, Membership, Registration, User Profiles plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 6.4.5.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administr...
- CVSS:
- 4.4
- Affected:
- up to 6.4.5.0
- Fixed in:
- 6.4.6.0
- Disclosed:
- Sep 9, 2024
CVE-2024-7655 on NVD →
Community by PeepSo – Social Network, Membership, Registration, User Profiles [peepso-core] < 6.3.1.2 (closed)
unknown
[en] Cross-Site Request Forgery (CSRF) vulnerability in PeepSo Community by PeepSo.This issue affects Community by PeepSo: from n/a through 6.3.1.1.
- Affected:
- up to 6.3.1.2
- Fixed in:
- 6.3.1.2
- Disclosed:
- Apr 12, 2024
CVE-2024-31251 on NVD →
Community by PeepSo – Social Network, Membership, Registration, User Profiles [peepso-core] < 6.2.7.1 (closed)
unknown
[en] Insertion of Sensitive Information into Log File vulnerability in PeepSo Community by PeepSo.This issue affects Community by PeepSo: from n/a through 6.2.7.0.
- Affected:
- up to 6.2.7.1
- Fixed in:
- 6.2.7.1
- Disclosed:
- Mar 28, 2024
CVE-2024-25923 on NVD →
Community by PeepSo – Social Network, Membership, Registration, User Profiles [peepso-core] < 6.1.0.0 (closed)
unknown
[en] Exposure of Sensitive Information to an Unauthorized Actor vulnerability in PeepSo Community by PeepSo.This issue affects Community by PeepSo: from n/a through 6.0.9.0.
- Affected:
- up to 6.1.0.0
- Fixed in:
- 6.1.0.0
- Disclosed:
- Mar 26, 2024
CVE-2023-27630 on NVD →
Community by PeepSo <= 6.2.7.0 - Unauthenticated Sensitive Information Disclosure via Log file
medium
The Community by PeepSo – Social Network, Membership, Registration, User Profiles plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 6.2.7.0. This makes it possible for unauthenticated attackers to extract sensitive data from log files.
- CVSS:
- 6.5
- Affected:
- up to 6.2.7.0
- Fixed in:
- 6.2.7.1
- Disclosed:
- Feb 14, 2024
CVE-2024-25923 on NVD →
Community by PeepSo – Social Network, Membership, Registration, User Profiles [peepso-core] < 6.3.1.2 (closed)
unknown
[en] The Community by PeepSo WordPress plugin before 6.3.1.2 does not sanitise and escape various parameters and generated URLs before outputting them back attributes, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin
- Affected:
- up to 6.3.1.2
- Fixed in:
- 6.3.1.2
- Disclosed:
- Jan 16, 2024
CVE-2024-0187 on NVD →
Community by PeepSo – Social Network, Membership, Registration, User Profiles [peepso-core] < 6.3.1.2 (closed)
unknown
[en] The Community by PeepSo WordPress plugin before 6.3.1.2 does not have CSRF check when creating a user post (visible on their wall in their profile page), which could allow attackers to make logged in users perform such action via a CSRF attack
- Affected:
- up to 6.3.1.2
- Fixed in:
- 6.3.1.2
- Disclosed:
- Jan 16, 2024
CVE-2023-7125 on NVD →
Community by PeepSo <= 6.3.1.1 - Reflected Cross-Site Scripting
medium
The Community by PeepSo plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and including, 6.3.1.1. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute i...
- CVSS:
- 6.1
- Affected:
- up to 6.3.1.1
- Fixed in:
- 6.3.1.2
- Disclosed:
- Jan 9, 2024
CVE-2024-0187 on NVD →
Community by PeepSo <= 6.3.1.1 - Cross-Site Request Forgery to User Post Creation
medium
The Community by PeepSo – Social Network, Membership, Registration, User Profiles plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 6.3.1.1. This is due to missing or incorrect nonce validation. This makes it possible for unauthenticated attackers to create user post...
- CVSS:
- 4.3
- Affected:
- up to 6.3.1.1
- Fixed in:
- 6.3.1.2
- Disclosed:
- Jan 9, 2024
CVE-2023-7125 on NVD →
Community by PeepSo – Social Network, Membership, Registration, User Profiles [peepso-core] < 6.2.3.0 (closed)
unknown
[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in PeepSo Community by PeepSo – Social Network, Membership, Registration, User Profiles allows Stored XSS.This issue affects Community by PeepSo – Social Network, Membership, Registration, User Profiles: from n/a thr...
- Affected:
- up to 6.2.3.0
- Fixed in:
- 6.2.3.0
- Disclosed:
- Nov 30, 2023
CVE-2023-47850 on NVD →
Community by PeepSo – Social Network, Membership, Registration, User Profiles [peepso-core] < 6.2.7.0 (closed)
unknown
[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in PeepSo Community by PeepSo – Social Network, Membership, Registration, User Profiles allows Reflected XSS.This issue affects Community by PeepSo – Social Network, Membership, Registration, User Profiles: from n/a...
- Affected:
- up to 6.2.7.0
- Fixed in:
- 6.2.7.0
- Disclosed:
- Nov 30, 2023
CVE-2023-48746 on NVD →
Community by PeepSo <= 6.2.6.0 - Reflected Cross-Site Scripting
medium
The Community by PeepSo – Social Network, Membership, Registration, User Profiles plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via an unknown parameter in all versions up to, and including, 6.2.6.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthentic...
- CVSS:
- 6.1
- Affected:
- up to 6.2.6.0
- Fixed in:
- 6.2.7.0
- Disclosed:
- Nov 24, 2023
CVE-2023-48746 on NVD →
Community by PeepSo – Social Network, Membership, Registration, User Profiles [peepso-core] < 6.2.0.0 (closed)
unknown
[en] Cross-Site Request Forgery (CSRF) vulnerability in PeepSo Download Community by PeepSo plugin <= 6.1.6.0 versions.
- Affected:
- up to 6.2.0.0
- Fixed in:
- 6.2.0.0
- Disclosed:
- Nov 22, 2023
CVE-2023-39925 on NVD →
Community by PeepSo <= 6.2.2.0 - Authenticated (Contributor+) Stored Cross-Site Scripting
medium
The Community by PeepSo – Social Network, Membership, Registration, User Profiles plugin for WordPress is vulnerable to Stored Cross-Site Scripting via user avatars in all versions up to, and including, 6.2.2.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possibl...
- CVSS:
- 6.4
- Affected:
- up to 6.2.2.0
- Fixed in:
- 6.2.3.0
- Disclosed:
- Nov 20, 2023
CVE-2023-47850 on NVD →
Community by PeepSo <= 6.1.6.0 - Cross-Site Request Forgery via delete
medium
The Community by PeepSo plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 6.1.6.0. This is due to missing or incorrect nonce validation on the delete function. This makes it possible for unauthenticated attackers to delete PeepSo posts via a forged request granted they c...
- CVSS:
- 4.3
- Affected:
- up to 6.1.6.0
- Fixed in:
- 6.2.0.0
- Disclosed:
- Nov 16, 2023
CVE-2023-39925 on NVD →
Community by PeepSo – Social Network, Membership, Registration, User Profiles [peepso-core] < 6.1.0.0 (closed)
unknown
[en] Cross-Site Request Forgery (CSRF) vulnerability in PeepSo Community by PeepSo – Social Network, Membership, Registration, User Profiles plugin <= 6.0.9.0 versions.
- Affected:
- up to 6.1.0.0
- Fixed in:
- 6.1.0.0
- Disclosed:
- Nov 9, 2023
CVE-2023-32092 on NVD →
Community by PeepSo <= 6.0.9.0 - Cross-Site Request Forgery to Field Duplication
medium
The Community by PeepSo plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 6.0.9.0. This is due to missing or incorrect nonce validation on the duplicate_field() function. This makes it possible for unauthenticated attackers to duplicate user fields via a forged request g...
- CVSS:
- 4.3
- Affected:
- up to 6.0.9.0
- Fixed in:
- 6.1.0.0
- Disclosed:
- May 12, 2023
CVE-2023-32092 on NVD →
Community by PeepSo <= 6.0.9.0 - Missing Authorization to Sensitive Information Exposure
medium
The Community by PeepSo plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 6.0.9.0 due to missing authorization checks on the action_admin_export() function. This makes it possible for unauthenticated attackers to trigger a system report export and obtain sensitive in...
- CVSS:
- 5.3
- Affected:
- up to 6.0.9.0
- Fixed in:
- 6.1.0.0
- Disclosed:
- May 5, 2023
CVE-2023-27630 on NVD →
Community by PeepSo – Social Network, Membership, Registration, User Profiles [peepso-core] < 6.0.3.0 (closed)
unknown
[en] Cross-Site Request Forgery (CSRF) vulnerability in PeepSo Community by PeepSo plugin <= 6.0.2.0 versions.
- Affected:
- up to 6.0.3.0
- Fixed in:
- 6.0.3.0
- Disclosed:
- May 3, 2023
CVE-2023-25967 on NVD →
Community by PeepSo – Social Network, Membership, Registration, User Profiles [peepso-core] < 6.0.3.0 (closed)
unknown
[en] Cross-Site Request Forgery (CSRF) vulnerability in PeepSo Community by PeepSo – Social Network, Membership, Registration, User Profiles plugin <= 6.0.2.0 versions.
- Affected:
- up to 6.0.3.0
- Fixed in:
- 6.0.3.0
- Disclosed:
- Apr 4, 2023
CVE-2022-41633 on NVD →
Community by PeepSo <= 6.0.2.0 - Cross-Site Request Forgery leading to Plugin/Subscription Deletion
high
The Community by PeepSo plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 6.0.2.0. This is due to missing or incorrect nonce validation in the 'peepso.php' file. This makes it possible for unauthenticated attackers to unsubscribe email subscribers or delete the peepso pl...
- CVSS:
- 8.1
- Affected:
- up to 6.0.2.0
- Fixed in:
- 6.0.3.0
- Disclosed:
- Feb 22, 2023
CVE-2023-25967 on NVD →
Community by PeepSo <= 6.0.2.0 - Cross Site Request Forgery
medium
The Community by PeepSo plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 6.0.2.0. This is due to missing or incorrect nonce validation on an unknown function. This makes it possible for unauthenticated attackers to perform an unknown action granted they can trick a site...
- CVSS:
- 5.4
- Affected:
- up to 6.0.2.0
- Fixed in:
- 6.0.3.0
- Disclosed:
- Feb 20, 2023
CVE-2022-41633 on NVD →
Community by PeepSo – Social Network, Membership, Registration, User Profiles [peepso-core] < 1.6.1 (closed)
unknown
[en] The peepso-core plugin before 1.6.1 for WordPress has PeepSoProfilePreferencesAjax->save() privilege escalation.
- Affected:
- up to 1.6.1
- Fixed in:
- 1.6.1
- Disclosed:
- Sep 16, 2019
CVE-2016-10968 on NVD →
Community by PeepSo – Social Network, Membership, Registration, User Profiles [peepso-core] < 1.6.1 (closed)
unknown
This plugin is prone to a privilege escalation vulnerability. It allows a logged in user to upgrade their account to be an administrator.
Update the plugin.
- Affected:
- up to 1.6.1
- Fixed in:
- 1.6.1
- Disclosed:
- Jun 29, 2016
Community by PeepSo – Social Network, Membership, Registration, User Profiles < 1.6.1 - Privilege Escalation
high
The peepso-core plugin before 1.6.1 for WordPress has PeepSoProfilePreferencesAjax->save() privilege escalation.
- CVSS:
- 8.8
- Affected:
- up to 1.6.0
- Fixed in:
- 1.6.1
- Disclosed:
- Jun 21, 2016
CVE-2016-10968 on NVD →