plugin

Phastpress Vulnerabilities

2 known security issues reported for the Phastpress WordPress plugin. Most recent disclosed Dec 22, 2025.

1 critical 1 medium

Running Phastpress on your site? Check whether your installed version is affected.

Scan your site free

PhastPress <= 3.7 - Unauthenticated Arbitrary File Read via Null Byte Injection

critical

The PhastPress plugin for WordPress is vulnerable to Unauthenticated Arbitrary File Read via null byte injection in all versions up to, and including, 3.7. This is due to a discrepancy between the extension validation in `getExtensionForURL()` which operates on URL-decoded paths, and `appendNormalized()` which strips e...

CVSS:
9.8
Affected:
up to 3.7
Fixed in:
3.8
Disclosed:
Dec 22, 2025

CVE-2025-14388 on NVD →

PhastPress <= 1.110 - Open Redirect

medium

There is an open redirect in the PhastPress WordPress plugin before 1.111 that allows an attacker to malform a request to a page with the plugin and then redirect the victim to a malicious page. There is also a support comment from another user one year ago (https://wordpress.org/support/topic/phast-php-used-for-remote...

CVSS:
6.1
Affected:
up to 1.110
Fixed in:
1.111
Disclosed:
Mar 19, 2021

CVE-2021-24210 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database