Surfer <= 1.6.4.574 - Missing Authorization
medium
The Surfer – WordPress Plugin plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 1.6.4.574. This makes it possible for unauthenticated attackers to perform an unauthorized action.
- CVSS:
- 5.3
- Affected:
- up to 1.6.4.574
- Fixed in:
- 1.6.5.584
- Disclosed:
- Sep 3, 2025
CVE-2025-58603 on NVD →
Surfer <= 1.5.0.502 - Authenticated (Administrator+) SQL Injection
medium
The Surfer plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.5.0.502 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with administrator-level access and ab...
- CVSS:
- 4.9
- Affected:
- up to 1.5.0.502
- Fixed in:
- 1.6.0.523
- Disclosed:
- Oct 15, 2024
CVE-2024-49299 on NVD →
Surfer <= 1.3.2.357 - Missing Authorization
medium
The Surfer plugin for WordPress is vulnerable to unauthorized access and modification of data due to missing capability checks on several functions, such as remove_post_draft_connection, check_draft_status, get_locations, get_ajax_surfer_connect_url, disconnect_surfer_from_wp, and check_connection_status called via AJ...
- CVSS:
- 5.4
- Affected:
- up to 1.3.2.357
- Fixed in:
- 1.3.3.379
- Disclosed:
- Sep 1, 2023
CVE-2023-35037 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database