plugin

Reciply Vulnerabilities

5 known security issues reported for the Reciply WordPress plugin. Most recent disclosed Feb 14, 2025.

1 critical 1 medium

Running Reciply on your site? Check whether your installed version is affected.

Scan your site free

Recip.ly Plugin [reciply] <= 1.1.8 (unfixed + closed)

unknown

[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in craig.edmunds@gmail.com Recip.ly allows Reflected XSS. This issue affects Recip.ly: from n/a through 1.1.8.

Affected:
up to 1.1.8
Fix:
No patched version reported
Disclosed:
Feb 14, 2025

CVE-2025-23598 on NVD →

Recip.ly Plugin <= 1.1.8 - Reflected Cross-Site Scripting

medium

The Recip.ly Plugin plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and including, 1.1.8 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successf...

CVSS:
6.1
Affected:
up to 1.1.8
Fix:
No patched version reported
Disclosed:
Jan 16, 2025

CVE-2025-23598 on NVD →

Recip.ly <= 1.1.7 - Unauthenticated Arbitrary File Upload in uploadImage.php

critical

The Recip.ly Plugin plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in uploadImage.php in all versions up to, and including, 1.1.7. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code exe...

CVSS:
9.8
Affected:
up to 1.1.7
Fixed in:
1.1.8
Disclosed:
Oct 16, 2023

CVE-2011-10004 on NVD →

Recip.ly Plugin [reciply] < 1.1.8 (closed)

unknown

[en] A vulnerability was found in reciply Plugin up to 1.1.7 on WordPress. It has been rated as critical. This issue affects some unknown processing of the file uploadImage.php. The manipulation leads to unrestricted upload. The attack may be initiated remotely. Upgrading to version 1.1.8 is able to address this issue....

Affected:
up to 1.1.8
Fixed in:
1.1.8
Disclosed:
Oct 16, 2023

CVE-2011-10004 on NVD →

Recip.ly Plugin [reciply] < 1.1.8 (closed)

unknown

WordPress Recip.ly plugin's "uploadImage.php" parameter is prone to a vulnerability which allows attackers to upload arbitrary files. This is because it fails to adequately clean up user-supplied input. In this way, the attackers can use this vulnerability to upload an arbitrary code and then run it in the context of t...

Affected:
up to 1.1.8
Fixed in:
1.1.8
Disclosed:
Jan 25, 2011

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database