simple-git < 3.16.0 - Remote Code Execution
high
The package simple-git is vulnerable to Remote Code Execution in versions before 3.16.0 via the clone(), pull(), push() and listRemote() methods due to improper input sanitization. This is due to an incomplete fix of CVE-2022-25912. WordPress plugins and themes may be using this package, however, they may not be vulner...
- CVSS:
- 8.1
- Affected:
- up to 1.3.0
- Fixed in:
- 1.3.0
- Disclosed:
- Feb 23, 2023
CVE-2022-25860 on NVD →
Terser < 4.8.1 and 5.0.0-5.14.1 - Regular Expression Denial of Service
medium
The package terser before 4.8.1, from 5.0.0 and before 5.14.2 are vulnerable to Regular Expression Denial of Service (ReDoS) due to insecure usage of regular expressions. As this package is used in some WordPress plugins, this could result in the impacted plugins being vulnerable.
- CVSS:
- 5.3
- Affected:
- up to 1.1.0
- Fixed in:
- 1.2.0
- Disclosed:
- Jul 15, 2022
CVE-2022-25858 on NVD →
terser (JS Package) < 5.14.2 - Denial of Service
low
The package terser before 4.8.1, from 5.0.0 and before 5.14.2 are vulnerable to Regular Expression Denial of Service (ReDoS) due to insecure usage of regular expressions. Some WordPress plugins and themes use this dependency, however, are not vulnerable to exploitation.
- CVSS:
- 3.7
- Affected:
- up to 1.1.0
- Fixed in:
- 1.2.0
- Disclosed:
- Jul 14, 2022
CVE-2022-25858 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database