Swiss Toolkit For WP <= 1.4.6 - Authenticated (Author+) Arbitrary File Upload via upload_extension_files()
high
The Swiss Toolkit For WP plugin for WordPress is vulnerable to arbitrary file upload due to a flawed file type validation bypass in the `upload_extension_files()` function in all versions up to, and including, 1.4.6. The `upload_extension_files()` function hooks into WordPress's `wp_check_filetype_and_ext` filter and u...
- CVSS:
- 8.8
- Affected:
- up to 1.4.6
- Fix:
- No patched version reported
- Disclosed:
- Jul 10, 2026
CVE-2026-2354 on NVD →
Swiss Toolkit For WP <= 1.4.0 - Missing Authorization
medium
The Swiss Toolkit For WP plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 1.4.0. This makes it possible for authenticated attackers, with Subscriber-level access and above, to perform an unauthorized action.
- CVSS:
- 4.3
- Affected:
- up to 1.4.0
- Fixed in:
- 1.4.1
- Disclosed:
- Mar 31, 2025
CVE-2025-31546 on NVD →
Swiss Toolkit For WP <= 1.4.1 - Missing Authorization
medium
The Swiss Toolkit For WP plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 1.4.1. This makes it possible for authenticated attackers, with Contributor-level access and above, to perform an unauthorized action.
- CVSS:
- 4.3
- Affected:
- up to 1.4.1
- Fix:
- No patched version reported
- Disclosed:
- Mar 31, 2025
CVE-2025-31544 on NVD →
Swiss Toolkit For WP [swiss-toolkit-for-wp] <= 1.3.0 (unfixed)
unknown
[en] Missing Authorization vulnerability in WP Messiah Swiss Toolkit For WP allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Swiss Toolkit For WP: from n/a through 1.3.0.
- Affected:
- up to 1.3.0
- Fix:
- No patched version reported
- Disclosed:
- Mar 31, 2025
CVE-2025-31544 on NVD →
Swiss Toolkit For WP [swiss-toolkit-for-wp] <= 1.3.0 (unfixed)
unknown
[en] Missing Authorization vulnerability in WP Messiah Swiss Toolkit For WP allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Swiss Toolkit For WP: from n/a through 1.3.0.
- Affected:
- up to 1.3.0
- Fix:
- No patched version reported
- Disclosed:
- Mar 31, 2025
CVE-2025-31546 on NVD →
Swiss Toolkit For WP [swiss-toolkit-for-wp] < 1.0.8
unknown
[en] The Swiss Toolkit For WP plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 1.0.7. This is due to the plugin storing custom data in post metadata without an underscore prefix. This makes it possible for authenticated attackers with contributor-level and above permissions...
- Affected:
- up to 1.0.8
- Fixed in:
- 1.0.8
- Disclosed:
- May 29, 2024
CVE-2024-5204 on NVD →
Swiss Toolkit For WP <= 1.0.7 - Authenticated (Contributor+) Authentication Bypass
high
The Swiss Toolkit For WP plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 1.0.7. This is due to the plugin storing custom data in post metadata without an underscore prefix. This makes it possible for authenticated attackers with contributor-level and above permissions to lo...
- CVSS:
- 8.8
- Affected:
- up to 1.0.7
- Fixed in:
- 1.0.8
- Disclosed:
- May 28, 2024
CVE-2024-5204 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database