plugin

Quttera Web Malware Scanner Vulnerabilities

6 known security issues reported for the Quttera Web Malware Scanner WordPress plugin. Most recent disclosed Aug 14, 2025.

2 medium 1 low

Running Quttera Web Malware Scanner on your site? Check whether your installed version is affected.

Scan your site free

Quttera Web Malware Scanner <= 3.5.1.41 - Authenticated (Administrator+) Server-Side Request Forgery

low

The Quttera Web Malware Scanner plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 3.5.1.41 via the 'RunExternalScan' function. This makes it possible for authenticated attackers, with Administrator-level access and above, to make web requests to arbitrary locations...

CVSS:
3.8
Affected:
up to 3.5.1.41
Fixed in:
3.5.2.1
Disclosed:
Aug 14, 2025

CVE-2025-8013 on NVD →

Quttera Web Malware Scanner [quttera-web-malware-scanner] < 3.4.2.1

unknown

[en] The Quttera Web Malware Scanner WordPress plugin before 3.4.2.1 doesn't restrict access to detailed scan logs, which allows a malicious actor to discover local paths and portions of the site's code

Affected:
up to 3.4.2.1
Fixed in:
3.4.2.1
Disclosed:
Dec 18, 2023

CVE-2023-6065 on NVD →

Quttera Web Malware Scanner [quttera-web-malware-scanner] < 3.4.2.1

unknown

[en] IThe Quttera Web Malware Scanner WordPress plugin before 3.4.2.1 does not validate user input used in a path, which could allow users with an admin role to perform path traversal attacks

Affected:
up to 3.4.2.1
Fixed in:
3.4.2.1
Disclosed:
Dec 18, 2023

CVE-2023-6222 on NVD →

Quttera Web Malware Scanner <= 3.4.1.48 - Authenticated (Administrator+) Directory Traversal via ShowFile

medium

The Quttera Web Malware Scanner plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 3.4.1.48 via the ShowFile function. This allows an administrator to view arbitrary files on the server.

CVSS:
6.8
Affected:
up to 3.4.1.48
Fixed in:
3.4.2.1
Disclosed:
Nov 21, 2023

CVE-2023-6222 on NVD →

Quttera Web Malware Scanner <= 3.4.1.48 - Sensitive Data Exposure

medium

The Quttera Web Malware Scanner plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.4.1.48 via easy to guess scan log file names. This makes it possible for unauthenticated attackers to extract sensitive data.

CVSS:
5.3
Affected:
up to 3.4.1.48
Fixed in:
3.4.2.1
Disclosed:
Nov 21, 2023

CVE-2023-6065 on NVD →

Quttera Web Malware Scanner [quttera-web-malware-scanner] < 3.5.2.1

unknown
Affected:
up to 3.5.2.1
Fixed in:
3.5.2.1

CVE-2025-8013 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database