plugin

Simplepress Vulnerabilities

28 known security issues reported for the Simplepress WordPress plugin. Most recent disclosed Mar 31, 2025.

1 critical 2 high 6 medium 1 low

Running Simplepress on your site? Check whether your installed version is affected.

Scan your site free

Simple:Press <= 6.10.5 - Missing Authorization

medium

The Simple:Press Forum plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the sp_move_post() function in all versions up to, and including, 6.11.5. This makes it possible for unauthenticated attackers to move posts.

CVSS:
5.3
Affected:
up to 6.11.5
Fixed in:
6.11.6
Disclosed:
Mar 31, 2025

CVE-2025-31386 on NVD →

Simple:Press Forum [simplepress] <= 6.10.11 (unfixed)

unknown

[en] Missing Authorization vulnerability in Simplepress Simple:Press allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Simple:Press: from n/a through 6.10.11.

Affected:
up to 6.10.11
Fix:
No patched version reported
Disclosed:
Mar 31, 2025

CVE-2025-31386 on NVD →

Simple:Press Forum [simplepress] <= 6.10.11 (unfixed)

unknown

[en] The Simple:Press Forum plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 6.10.11. This is due to missing or incorrect nonce validation on the 'sp_save_edited_post' function. This makes it possible for unauthenticated attackers to modify a forum post via a forged...

Affected:
up to 6.10.11
Fix:
No patched version reported
Disclosed:
Mar 1, 2025

CVE-2024-13518 on NVD →

Simple:Press <= 6.10.12 - Cross-Site Request Forgery to Unauthorized Post Editing

medium

The Simple:Press Forum plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 6.10.12. This is due to missing or incorrect nonce validation on the 'sp_save_edited_post' function. This makes it possible for unauthenticated attackers to modify a forum post via a forged requ...

CVSS:
4.3
Affected:
up to 6.10.12
Fixed in:
6.10.13
Disclosed:
Feb 28, 2025

CVE-2024-13518 on NVD →

Simple:Press Forum [simplepress] < 6.10.11

unknown

[en] The Simple:Press Forum WordPress plugin before 6.10.11 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting.

Affected:
up to 6.10.11
Fixed in:
6.10.11
Disclosed:
Feb 26, 2025

CVE-2024-10483 on NVD →

Simple:Press Forum [simplepress] < 6.10.12

unknown

[en] The Simple:Press Forum plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 's' parameter in all versions up to, and including, 6.10.11 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages t...

Affected:
up to 6.10.12
Fixed in:
6.10.12
Disclosed:
Jan 30, 2025

CVE-2024-12409 on NVD →

Simple:Press Forum <= 6.10.11 - Reflected Cross-Site Scripting

medium

The Simple:Press Forum plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 's' parameter in all versions up to, and including, 6.10.11 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that e...

CVSS:
6.1
Affected:
up to 6.10.11
Fixed in:
6.10.12
Disclosed:
Jan 29, 2025

CVE-2024-12409 on NVD →

Simple:Press Forum <= 6.10.10 - Reflected Cross-Site Scripting via msearch

medium

The Simple:Press Forum plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'msearch' parameter in all versions up to, and including, 6.10.10 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages...

CVSS:
6.1
Affected:
up to 6.10.10
Fixed in:
6.10.11
Disclosed:
Jan 17, 2025

CVE-2024-10483 on NVD →

Simple:Press Forum [simplepress] < 6.10.11

unknown

The Simple:Press Forum plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'msearch' parameter in all versions up to, and including, 6.10.10 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages...

Affected:
up to 6.10.11
Fixed in:
6.10.11
Disclosed:
Jan 17, 2025

Simple:Press Forum [simplepress] < 6.10.11

unknown

<p>WordPress Simple:Press Plugin <= 6.10.10 is vulnerable to Cross Site Scripting (XSS)</p><p>Software: Simple:Press</p><p>Fixed in version 6.10.11 </p><p>Affected Version <= 6.10.10</p>

Affected:
up to 6.10.11
Fixed in:
6.10.11
Disclosed:
Jan 17, 2025

Simple:Press Forum [simplepress] < 6.6.1

unknown

[en] The Simple:Press – WordPress Forum Plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the ~/admin/resources/jscript/ajaxupload/sf-uploader.php file in versions up to, and including, 6.6.0. This makes it possible for attackers to upload arbitrary files on the affecte...

Affected:
up to 6.6.1
Fixed in:
6.6.1
Disclosed:
Oct 20, 2023

CVE-2020-36706 on NVD →

Simple:Press <= 6.8 - Authenticated (Subscriber+) Path Traversal to Arbitrary File Deletion

high

The Simple:Press plugin for WordPress is vulnerable to Path Traversal in versions up to, and including, 6.8 via the 'file' parameter which can be manipulated during user avatar deletion. This makes it possible with attackers, with minimal permissions such as a subscriber, to supply paths to arbitrary files on the serve...

CVSS:
8.1
Affected:
up to 6.8
Fixed in:
6.8.1
Disclosed:
Nov 29, 2022

CVE-2022-4030 on NVD →

Simple:Press <= 6.8 - Unauthenticated Stored Cross-Site Scripting via Forum Replies

high

The Simple:Press plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'postitem' parameter manipulated during a forum response in versions up to, and including, 6.8 due to insufficient input sanitization and output escaping that makes injecting object and embed tags possible. This makes it possible...

CVSS:
7.2
Affected:
up to 6.8
Fixed in:
6.8.1
Disclosed:
Nov 29, 2022

CVE-2022-4027 on NVD →

Simple:Press <= 6.8 - Authenticated (Subscriber+) Stored Cross-Site Scripting via Profile Signatures

medium

The Simple:Press plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'postitem' parameter manipulated during the profile-save action when modifying a profile signature in versions up to, and including, 6.8 due to insufficient input sanitization and output escaping that makes injecting object and e...

CVSS:
6.4
Affected:
up to 6.8
Fixed in:
6.8.1
Disclosed:
Nov 29, 2022

CVE-2022-4028 on NVD →

Simple:Press <= 6.8 - Reflected Cross-Site Scripting via Cookie Value

medium

The Simple:Press plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'sforum_[md5 hash of the WordPress URL]' cookie value in versions up to, and including, 6.8 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary w...

CVSS:
4.7
Affected:
up to 6.8
Fixed in:
6.8.1
Disclosed:
Nov 29, 2022

CVE-2022-4029 on NVD →

Simple:Press <= 6.8 - Authenticated (Admin+) Path Traversal to Arbitrary File Modification

low

The Simple:Press plugin for WordPress is vulnerable to arbitrary file modifications in versions up to, and including, 6.8 via the 'file' parameter which does not properly restrict files to be edited in the context of the plugin. This makes it possible with attackers, with high-level permissions such as an administrator...

CVSS:
3.8
Affected:
up to 6.8
Fixed in:
6.8.1
Disclosed:
Nov 29, 2022

CVE-2022-4031 on NVD →

Simple:Press Forum [simplepress] < 6.8.1

unknown

[en] The Simple:Press plugin for WordPress is vulnerable to arbitrary file modifications in versions up to, and including, 6.8 via the 'file' parameter which does not properly restrict files to be edited in the context of the plugin. This makes it possible with attackers, with high-level permissions such as an administ...

Affected:
up to 6.8.1
Fixed in:
6.8.1
Disclosed:
Nov 29, 2022

CVE-2022-4031 on NVD →

Simple:Press Forum [simplepress] < 6.8.1

unknown

[en] The Simple:Press plugin for WordPress is vulnerable to Path Traversal in versions up to, and including, 6.8 via the 'file' parameter which can be manipulated during user avatar deletion. This makes it possible with attackers, with minimal permissions such as a subscriber, to supply paths to arbitrary files on the...

Affected:
up to 6.8.1
Fixed in:
6.8.1
Disclosed:
Nov 29, 2022

CVE-2022-4030 on NVD →

Simple:Press Forum [simplepress] < 6.8.1

unknown

[en] The Simple:Press plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'sforum_[md5 hash of the WordPress URL]' cookie value in versions up to, and including, 6.8 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitr...

Affected:
up to 6.8.1
Fixed in:
6.8.1
Disclosed:
Nov 29, 2022

CVE-2022-4029 on NVD →

Simple:Press Forum [simplepress] < 6.8.1

unknown

[en] The Simple:Press plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'postitem' parameter manipulated during the profile-save action when modifying a profile signature in versions up to, and including, 6.8 due to insufficient input sanitization and output escaping that makes injecting object...

Affected:
up to 6.8.1
Fixed in:
6.8.1
Disclosed:
Nov 29, 2022

CVE-2022-4028 on NVD →

Simple:Press Forum [simplepress] < 6.8.1

unknown

[en] The Simple:Press plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'postitem' parameter manipulated during a forum response in versions up to, and including, 6.8 due to insufficient input sanitization and output escaping that makes injecting object and embed tags possible. This makes it pos...

Affected:
up to 6.8.1
Fixed in:
6.8.1
Disclosed:
Nov 29, 2022

CVE-2022-4027 on NVD →

Simple:Press – WordPress Forum Plugin <= 6.6.0 - Arbitrary File Upload

critical

The Simple:Press – WordPress Forum Plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the ~/admin/resources/jscript/ajaxupload/sf-uploader.php file in versions up to, and including, 6.6.0. This makes it possible for attackers to upload arbitrary files on the affected sit...

CVSS:
9.8
Affected:
up to 6.6.1
Fixed in:
6.6.1
Disclosed:
Sep 25, 2020

CVE-2020-36706 on NVD →

Simple:Press Forum [simplepress] < 6.6.1

unknown

The Simple:Press – WordPress Forum Plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the ~/admin/resources/jscript/ajaxupload/sf-uploader.php file in versions up to, and including, 6.6.0. This makes it possible for attackers to upload arbitrary files on the affected sit...

Affected:
up to 6.6.1
Fixed in:
6.6.1
Disclosed:
Sep 25, 2020

Simple:Press Forum [simplepress] < 6.8.1

unknown

Update the WordPress Simple:Press plugin to the latest available version (at least 6.8.1). Luca Greeb discovered and reported this Cross Site Scripting (XSS) vulnerability in WordPress Simple:Press Plugin. This could allow a malicious actor to inject malicious scripts, such as redirects, advertisements, and other HTML...

Affected:
up to 6.8.1
Fixed in:
6.8.1

Simple:Press Forum [simplepress] < 6.8.1

unknown

Update the WordPress Simple:Press plugin to the latest available version (at least 6.8.1). Luca Greeb discovered and reported this Directory Traversal vulnerability in WordPress Simple:Press Plugin. This could allow a malicious actor to see all files in a given directory or determine if certain files/directories exist...

Affected:
up to 6.8.1
Fixed in:
6.8.1

Simple:Press Forum [simplepress] < 6.6.1

unknown

Jerome Bruandet, from NinTechNet, discovered a broken access control issue in the plugin, which could lead to unauthenticated arbitrary file and RCE.

Affected:
up to 6.6.1
Fixed in:
6.6.1

Simple:Press Forum [simplepress] < 6.8.1

unknown

Update the WordPress Simple:Press plugin to the latest available version (at least 6.8.1). Luca Greeb discovered and reported this Directory Traversal vulnerability in WordPress Simple:Press Plugin. This could allow a malicious actor to see all files in a given directory or determine if certain files/directories exist...

Affected:
up to 6.8.1
Fixed in:
6.8.1

Simple:Press Forum [simplepress] < 6.6.1

unknown

Update the WordPress Simple:Press plugin to the latest available version (at least 6.6.1). Jerome Bruandet (NinTechNet) discovered and reported this Arbitrary File Upload vulnerability in WordPress Simple:Press Plugin. This could allow a malicious actor to upload any type of file to your website. This can include backd...

Affected:
up to 6.6.1
Fixed in:
6.6.1

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database