plugin

Simply Static Vulnerabilities

5 known security issues reported for the Simply Static WordPress plugin. Most recent disclosed Apr 24, 2024.

2 medium

Running Simply Static on your site? Check whether your installed version is affected.

Scan your site free

Simply Static &#8211; The WordPress Static Site Generator [simply-static] < 3.1.4

unknown

[en] Insertion of Sensitive Information into Log File vulnerability in Patrick Posner Simply Static.This issue affects Simply Static: from n/a through 3.1.3.

Affected:
up to 3.1.4
Fixed in:
3.1.4
Disclosed:
Apr 24, 2024

CVE-2024-32825 on NVD →

Simply Static <= 3.1.3 - Unauthenticated Information Exposure

medium

The Simply Static plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.1.3 through publicly exposed log files. This makes it possible for unauthenticated attackers to view potentially sensitive information contained in the exposed log files.

CVSS:
5.3
Affected:
up to 3.1.3
Fixed in:
3.1.4
Disclosed:
Apr 22, 2024

CVE-2024-32825 on NVD →

Simply Static &#8211; The WordPress Static Site Generator [simply-static] < 3.1.4

unknown

[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Patrick Posner Simply Static allows Stored XSS.This issue affects Simply Static: from n/a through 3.1.3.

Affected:
up to 3.1.4
Fixed in:
3.1.4
Disclosed:
Mar 27, 2024

CVE-2024-30178 on NVD →

Simply Static <= 3.1.3 - Authenticated (Administrator+) Stored Cross-Site Scripting

medium

The Simply Static plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 3.1.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arb...

CVSS:
5.5
Affected:
up to 3.1.3
Fixed in:
3.1.4
Disclosed:
Mar 25, 2024

CVE-2024-30178 on NVD →

Simply Static &#8211; The WordPress Static Site Generator [simply-static] < 1.7.1

unknown

WordPress Simply Static Plugin <= 1.7.0 fails to check for a valid nonce when plugin's settings are saved. Also, some of the settings are shown on the front-end without escaping them. Update the plugin.

Affected:
up to 1.7.1
Fixed in:
1.7.1
Disclosed:
Oct 21, 2016

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database