plugin

Plugins On Steroids Vulnerabilities

3 known security issues reported for the Plugins On Steroids WordPress plugin. Most recent disclosed Jul 27, 2026.

1 high 2 medium

Running Plugins On Steroids on your site? Check whether your installed version is affected.

Scan your site free

Eazy Plugin Manager <= 4.4.1 - Authenticated (Subscriber+) Privilege Escalation via pos_get_option AJAX Action and admin/login REST Endpoint

high

The Eazy Plugin Manager – Powerful Plugin Management Solution for WordPress plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 4.4.1. This is due to insufficient authorization on the `wp_ajax_pos_get_option` AJAX handler, which verifies only a nonce that is localized to eve...

CVSS:
8.8
Affected:
up to 4.4.1
Fix:
No patched version reported
Disclosed:
Jul 27, 2026

CVE-2026-14328 on NVD →

Eazy Plugin Manager <= 4.3.0 - Missing Authorization

medium

The Eazy Plugin Manager – Powerful Plugin Management Solution for WordPress plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 4.3.0. This makes it possible for authenticated attackers, with Subscriber-level access and above, t...

CVSS:
4.3
Affected:
up to 4.3.0
Fixed in:
4.4.0
Disclosed:
Apr 9, 2025

CVE-2025-32542 on NVD →

Eazy Plugin Manager <= 4.1.2 - Missing Authorization via update_options

medium

The Eazy Plugin Manager – Powerful Plugin Management Solution for WordPress plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'update_options' function in all versions up to, and including, 4.1.2. This makes it possible for authenticated attackers, with sub...

CVSS:
4.3
Affected:
up to 4.1.2
Fixed in:
4.1.3
Disclosed:
Dec 27, 2023

CVE-2023-51482 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database