Ally - WordPress Ally - Web Accessibility & Usability plugin <= 4.0.3 - Unauthenticated SQL Injection via URL Path vulnerability
critical
WordPress Ally - Web Accessibility & Usability plugin <= 4.0.3 - Unauthenticated SQL Injection via URL Path vulnerability
- CVSS:
- 9.3
- Affected:
- up to 4.0.3
- Fixed in:
- 4.1.0
- Disclosed:
- Mar 11, 2026
Ally – Web Accessibility & Usability <= 4.0.3 - Unauthenticated SQL Injection via URL Path
high
The Ally – Web Accessibility & Usability plugin for WordPress is vulnerable to SQL Injection via the URL path in all versions up to, and including, 4.0.3. This is due to insufficient escaping on the user-supplied URL parameter in the `get_global_remediations()` method, where it is directly concatenated into an SQL JOIN...
- CVSS:
- 7.5
- Affected:
- up to 4.0.3
- Fixed in:
- 4.1.0
- Disclosed:
- Mar 10, 2026
CVE-2026-2413 on NVD →
Ally < 4.1.0 - Unauthenticated SQLi via URL Path
unknown
- Affected:
- up to 4.1.0
- Fixed in:
- 4.1.0
- Disclosed:
- Mar 10, 2026
CVE-2026-2413 on NVD →
Ally <= 4.0.2 - Missing Authorization
medium
The Ally plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 4.0.2. This makes it possible for unauthenticated attackers to perform an unauthorized action.
- CVSS:
- 5.3
- Affected:
- up to 4.0.2
- Fixed in:
- 4.0.3
- Disclosed:
- Feb 19, 2026
CVE-2026-25386 on NVD →
Ally < 4.0.3 - Missing Authorization
medium
- Affected:
- up to 4.0.3
- Fixed in:
- 4.0.3
- Disclosed:
- Feb 19, 2026
CVE-2026-25386 on NVD →
Ally - Web Accessibility & Usability <= 3.8.0 - Cross-Site Request Forgery to Plugin Settings Update
medium
The Ally – Web Accessibility & Usability plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.8.0. This is due to missing or incorrect nonce validation on the enable_unfiltered_files_upload function. This makes it possible for unauthenticated attackers to enable unfil...
- CVSS:
- 4.3
- Affected:
- up to 3.8.0
- Fixed in:
- 3.8.1
- Disclosed:
- Oct 15, 2025
CVE-2025-10700 on NVD →
Ally - Web Accessibility & Usability < 3.8.1 - Cross-Site Request Forgery to Plugin Settings Update
medium
- Affected:
- up to 3.8.1
- Fixed in:
- 3.8.1
- Disclosed:
- Oct 15, 2025
CVE-2025-10700 on NVD →
One Click Accessibility <= 3.1.0 - Authenticated (Administrator+) Stored Cross-Site Scripting
medium
The One Click Accessibility plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 3.1.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level access and above, to inject arbitrary web scripts...
- CVSS:
- 4.4
- Affected:
- up to 3.1.0
- Fixed in:
- 3.2.0
- Disclosed:
- Apr 9, 2025
CVE-2025-32640 on NVD →
One Click Accessibility < 3.2.0 - Authenticated (Administrator+) Stored Cross-Site Scripting
medium
- Affected:
- up to 3.2.0
- Fixed in:
- 3.2.0
- Disclosed:
- Apr 9, 2025
CVE-2025-32640 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database