Simple:Press <= 6.10.5 - Missing Authorization
medium
The Simple:Press Forum plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the sp_move_post() function in all versions up to, and including, 6.11.5. This makes it possible for unauthenticated attackers to move posts.
- CVSS:
- 5.3
- Affected:
- up to 6.11.5
- Fixed in:
- 6.11.6
- Disclosed:
- Mar 31, 2025
CVE-2025-31386 on NVD →
Simple:Press Forum [simplepress] <= 6.10.11 (unfixed)
unknown
[en] Missing Authorization vulnerability in Simplepress Simple:Press allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Simple:Press: from n/a through 6.10.11.
- Affected:
- up to 6.10.11
- Fix:
- No patched version reported
- Disclosed:
- Mar 31, 2025
CVE-2025-31386 on NVD →
Simple:Press Forum [simplepress] <= 6.10.11 (unfixed)
unknown
[en] The Simple:Press Forum plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 6.10.11. This is due to missing or incorrect nonce validation on the 'sp_save_edited_post' function. This makes it possible for unauthenticated attackers to modify a forum post via a forged...
- Affected:
- up to 6.10.11
- Fix:
- No patched version reported
- Disclosed:
- Mar 1, 2025
CVE-2024-13518 on NVD →
Simple:Press <= 6.10.12 - Cross-Site Request Forgery to Unauthorized Post Editing
medium
The Simple:Press Forum plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 6.10.12. This is due to missing or incorrect nonce validation on the 'sp_save_edited_post' function. This makes it possible for unauthenticated attackers to modify a forum post via a forged requ...
- CVSS:
- 4.3
- Affected:
- up to 6.10.12
- Fixed in:
- 6.10.13
- Disclosed:
- Feb 28, 2025
CVE-2024-13518 on NVD →
Simple:Press Forum [simplepress] < 6.10.11
unknown
[en] The Simple:Press Forum WordPress plugin before 6.10.11 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting.
- Affected:
- up to 6.10.11
- Fixed in:
- 6.10.11
- Disclosed:
- Feb 26, 2025
CVE-2024-10483 on NVD →
Simple:Press Forum [simplepress] < 6.10.12
unknown
[en] The Simple:Press Forum plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 's' parameter in all versions up to, and including, 6.10.11 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages t...
- Affected:
- up to 6.10.12
- Fixed in:
- 6.10.12
- Disclosed:
- Jan 30, 2025
CVE-2024-12409 on NVD →
Simple:Press Forum <= 6.10.11 - Reflected Cross-Site Scripting
medium
The Simple:Press Forum plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 's' parameter in all versions up to, and including, 6.10.11 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that e...
- CVSS:
- 6.1
- Affected:
- up to 6.10.11
- Fixed in:
- 6.10.12
- Disclosed:
- Jan 29, 2025
CVE-2024-12409 on NVD →
Simple:Press Forum <= 6.10.10 - Reflected Cross-Site Scripting via msearch
medium
The Simple:Press Forum plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'msearch' parameter in all versions up to, and including, 6.10.10 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages...
- CVSS:
- 6.1
- Affected:
- up to 6.10.10
- Fixed in:
- 6.10.11
- Disclosed:
- Jan 17, 2025
CVE-2024-10483 on NVD →
Simple:Press Forum [simplepress] < 6.10.11
unknown
The Simple:Press Forum plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'msearch' parameter in all versions up to, and including, 6.10.10 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages...
- Affected:
- up to 6.10.11
- Fixed in:
- 6.10.11
- Disclosed:
- Jan 17, 2025
Simple:Press Forum [simplepress] < 6.10.11
unknown
<p>WordPress Simple:Press Plugin <= 6.10.10 is vulnerable to Cross Site Scripting (XSS)</p><p>Software: Simple:Press</p><p>Fixed in version 6.10.11 </p><p>Affected Version <= 6.10.10</p>
- Affected:
- up to 6.10.11
- Fixed in:
- 6.10.11
- Disclosed:
- Jan 17, 2025
Simple:Press Forum [simplepress] < 6.6.1
unknown
[en] The Simple:Press – WordPress Forum Plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the ~/admin/resources/jscript/ajaxupload/sf-uploader.php file in versions up to, and including, 6.6.0. This makes it possible for attackers to upload arbitrary files on the affecte...
- Affected:
- up to 6.6.1
- Fixed in:
- 6.6.1
- Disclosed:
- Oct 20, 2023
CVE-2020-36706 on NVD →
Simple:Press <= 6.8 - Authenticated (Subscriber+) Path Traversal to Arbitrary File Deletion
high
The Simple:Press plugin for WordPress is vulnerable to Path Traversal in versions up to, and including, 6.8 via the 'file' parameter which can be manipulated during user avatar deletion. This makes it possible with attackers, with minimal permissions such as a subscriber, to supply paths to arbitrary files on the serve...
- CVSS:
- 8.1
- Affected:
- up to 6.8
- Fixed in:
- 6.8.1
- Disclosed:
- Nov 29, 2022
CVE-2022-4030 on NVD →
Simple:Press <= 6.8 - Unauthenticated Stored Cross-Site Scripting via Forum Replies
high
The Simple:Press plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'postitem' parameter manipulated during a forum response in versions up to, and including, 6.8 due to insufficient input sanitization and output escaping that makes injecting object and embed tags possible. This makes it possible...
- CVSS:
- 7.2
- Affected:
- up to 6.8
- Fixed in:
- 6.8.1
- Disclosed:
- Nov 29, 2022
CVE-2022-4027 on NVD →
Simple:Press <= 6.8 - Authenticated (Subscriber+) Stored Cross-Site Scripting via Profile Signatures
medium
The Simple:Press plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'postitem' parameter manipulated during the profile-save action when modifying a profile signature in versions up to, and including, 6.8 due to insufficient input sanitization and output escaping that makes injecting object and e...
- CVSS:
- 6.4
- Affected:
- up to 6.8
- Fixed in:
- 6.8.1
- Disclosed:
- Nov 29, 2022
CVE-2022-4028 on NVD →
Simple:Press <= 6.8 - Reflected Cross-Site Scripting via Cookie Value
medium
The Simple:Press plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'sforum_[md5 hash of the WordPress URL]' cookie value in versions up to, and including, 6.8 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary w...
- CVSS:
- 4.7
- Affected:
- up to 6.8
- Fixed in:
- 6.8.1
- Disclosed:
- Nov 29, 2022
CVE-2022-4029 on NVD →
Simple:Press <= 6.8 - Authenticated (Admin+) Path Traversal to Arbitrary File Modification
low
The Simple:Press plugin for WordPress is vulnerable to arbitrary file modifications in versions up to, and including, 6.8 via the 'file' parameter which does not properly restrict files to be edited in the context of the plugin. This makes it possible with attackers, with high-level permissions such as an administrator...
- CVSS:
- 3.8
- Affected:
- up to 6.8
- Fixed in:
- 6.8.1
- Disclosed:
- Nov 29, 2022
CVE-2022-4031 on NVD →
Simple:Press Forum [simplepress] < 6.8.1
unknown
[en] The Simple:Press plugin for WordPress is vulnerable to arbitrary file modifications in versions up to, and including, 6.8 via the 'file' parameter which does not properly restrict files to be edited in the context of the plugin. This makes it possible with attackers, with high-level permissions such as an administ...
- Affected:
- up to 6.8.1
- Fixed in:
- 6.8.1
- Disclosed:
- Nov 29, 2022
CVE-2022-4031 on NVD →
Simple:Press Forum [simplepress] < 6.8.1
unknown
[en] The Simple:Press plugin for WordPress is vulnerable to Path Traversal in versions up to, and including, 6.8 via the 'file' parameter which can be manipulated during user avatar deletion. This makes it possible with attackers, with minimal permissions such as a subscriber, to supply paths to arbitrary files on the...
- Affected:
- up to 6.8.1
- Fixed in:
- 6.8.1
- Disclosed:
- Nov 29, 2022
CVE-2022-4030 on NVD →
Simple:Press Forum [simplepress] < 6.8.1
unknown
[en] The Simple:Press plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'sforum_[md5 hash of the WordPress URL]' cookie value in versions up to, and including, 6.8 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitr...
- Affected:
- up to 6.8.1
- Fixed in:
- 6.8.1
- Disclosed:
- Nov 29, 2022
CVE-2022-4029 on NVD →
Simple:Press Forum [simplepress] < 6.8.1
unknown
[en] The Simple:Press plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'postitem' parameter manipulated during the profile-save action when modifying a profile signature in versions up to, and including, 6.8 due to insufficient input sanitization and output escaping that makes injecting object...
- Affected:
- up to 6.8.1
- Fixed in:
- 6.8.1
- Disclosed:
- Nov 29, 2022
CVE-2022-4028 on NVD →
Simple:Press Forum [simplepress] < 6.8.1
unknown
[en] The Simple:Press plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'postitem' parameter manipulated during a forum response in versions up to, and including, 6.8 due to insufficient input sanitization and output escaping that makes injecting object and embed tags possible. This makes it pos...
- Affected:
- up to 6.8.1
- Fixed in:
- 6.8.1
- Disclosed:
- Nov 29, 2022
CVE-2022-4027 on NVD →
Simple:Press – WordPress Forum Plugin <= 6.6.0 - Arbitrary File Upload
critical
The Simple:Press – WordPress Forum Plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the ~/admin/resources/jscript/ajaxupload/sf-uploader.php file in versions up to, and including, 6.6.0. This makes it possible for attackers to upload arbitrary files on the affected sit...
- CVSS:
- 9.8
- Affected:
- up to 6.6.1
- Fixed in:
- 6.6.1
- Disclosed:
- Sep 25, 2020
CVE-2020-36706 on NVD →
Simple:Press Forum [simplepress] < 6.6.1
unknown
The Simple:Press – WordPress Forum Plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the ~/admin/resources/jscript/ajaxupload/sf-uploader.php file in versions up to, and including, 6.6.0. This makes it possible for attackers to upload arbitrary files on the affected sit...
- Affected:
- up to 6.6.1
- Fixed in:
- 6.6.1
- Disclosed:
- Sep 25, 2020
Simple:Press Forum [simplepress] < 6.8.1
unknown
Update the WordPress Simple:Press plugin to the latest available version (at least 6.8.1).
Luca Greeb discovered and reported this Cross Site Scripting (XSS) vulnerability in WordPress Simple:Press Plugin. This could allow a malicious actor to inject malicious scripts, such as redirects, advertisements, and other HTML...
- Affected:
- up to 6.8.1
- Fixed in:
- 6.8.1
Simple:Press Forum [simplepress] < 6.8.1
unknown
Update the WordPress Simple:Press plugin to the latest available version (at least 6.8.1).
Luca Greeb discovered and reported this Directory Traversal vulnerability in WordPress Simple:Press Plugin. This could allow a malicious actor to see all files in a given directory or determine if certain files/directories exist...
- Affected:
- up to 6.8.1
- Fixed in:
- 6.8.1
Simple:Press Forum [simplepress] < 6.6.1
unknown
Jerome Bruandet, from NinTechNet, discovered a broken access control issue in the plugin, which could lead to unauthenticated arbitrary file and RCE.
- Affected:
- up to 6.6.1
- Fixed in:
- 6.6.1
Simple:Press Forum [simplepress] < 6.8.1
unknown
Update the WordPress Simple:Press plugin to the latest available version (at least 6.8.1).
Luca Greeb discovered and reported this Directory Traversal vulnerability in WordPress Simple:Press Plugin. This could allow a malicious actor to see all files in a given directory or determine if certain files/directories exist...
- Affected:
- up to 6.8.1
- Fixed in:
- 6.8.1
Simple:Press Forum [simplepress] < 6.6.1
unknown
Update the WordPress Simple:Press plugin to the latest available version (at least 6.6.1).
Jerome Bruandet (NinTechNet) discovered and reported this Arbitrary File Upload vulnerability in WordPress Simple:Press Plugin. This could allow a malicious actor to upload any type of file to your website. This can include backd...
- Affected:
- up to 6.6.1
- Fixed in:
- 6.6.1
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database