Publitio <= 2.2.3 - Authenticated (Contributor+) Information Exposure
medium
The Publitio plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.2.3. This makes it possible for authenticated attackers, with Contributor-level access and above, to extract sensitive user or configuration data.
- CVSS:
- 4.3
- Affected:
- up to 2.2.3
- Fix:
- No patched version reported
- Disclosed:
- Oct 10, 2025
CVE-2025-62947 on NVD →
Publitio <= 2.2.1 - Authenticated (Contributor+) Server-Side Request Forgery
medium
The Publitio plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 2.2.1. This makes it possible for authenticated attackers, with Contributor-level access and above, to make web requests to arbitrary locations originating from the web application which can be used to q...
- CVSS:
- 6.4
- Affected:
- up to 2.2.1
- Fixed in:
- 2.2.2
- Disclosed:
- Sep 22, 2025
CVE-2025-58962 on NVD →
Publitio <= 2.2.1 - Authenticated (Contributor+) Arbitrary File Read
medium
The Publitio plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 2.2.1. This makes it possible for authenticated attackers, with Contributor-level access and above, to read the contents of arbitrary files on the server, which can contain sensitive information.
- CVSS:
- 6.5
- Affected:
- up to 2.2.1
- Fixed in:
- 2.2.2
- Disclosed:
- Apr 3, 2025
CVE-2025-31800 on NVD →
Publitio <= 2.1.8 - Missing Authorization
medium
The Publitio plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 2.1.8. This makes it possible for authenticated attackers, with Subscriber-level access and above, to perform an unauthorized action.
- CVSS:
- 4.3
- Affected:
- up to 2.1.8
- Fixed in:
- 2.1.9
- Disclosed:
- Apr 1, 2025
CVE-2025-31799 on NVD →
Publitio <= 2.1.8 - Missing Authorization
medium
The Publitio plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the update_settings() function in all versions up to, and including, 2.1.8. This makes it possible for authenticated attackers, with Subscriber-level access and above, to update plugin settings.
- CVSS:
- 4.3
- Affected:
- up to 2.1.8
- Fixed in:
- 2.1.9
- Disclosed:
- Apr 1, 2025
CVE-2025-31798 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database