plugin

The Moneytizer Vulnerabilities

9 known security issues reported for the The Moneytizer WordPress plugin. Most recent disclosed Feb 22, 2026.

2 high 3 medium

Running The Moneytizer on your site? Check whether your installed version is affected.

Scan your site free

The Moneytizer <= 10.0.10 - Missing Authorization

medium

The The Moneytizer plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 10.0.10. This makes it possible for unauthenticated attackers to perform an unauthorized action.

CVSS:
5.3
Affected:
up to 10.0.10
Fix:
No patched version reported
Disclosed:
Feb 22, 2026

CVE-2026-39685 on NVD →

The Moneytizer <= 10.0.9 - Authenticated (Contributor+) Stored Cross-Site Scripting

medium

The The Moneytizer plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 10.0.9 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages...

CVSS:
6.4
Affected:
up to 10.0.9
Fixed in:
10.0.10
Disclosed:
Dec 31, 2025

CVE-2025-62756 on NVD →

The Moneytizer [the-moneytizer] <= 10.0.6 (unfixed)

unknown

[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in lvaudore The Moneytizer allows DOM-Based XSS.This issue affects The Moneytizer: from n/a through 10.0.6.

Affected:
up to 10.0.6
Fix:
No patched version reported
Disclosed:
Dec 31, 2025

CVE-2025-62756 on NVD →

The Moneytizer [the-moneytizer] < 10.0.1 (closed)

unknown

[en] The The Moneytizer plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 9.5.20. This is due to missing or incorrect nonce validation on multiple AJAX functions. This makes it possible for unauthenticated attackers to to update and retrieve billing and bank details,...

Affected:
up to 10.0.1
Fixed in:
10.0.1
Disclosed:
Jun 6, 2024

CVE-2023-6968 on NVD →

The Moneytizer [the-moneytizer] < 10.0.1 (closed)

unknown

[en] The The Moneytizer plugin for WordPress is vulnerable to unauthorized access of data, modification of data, and loss of data due to a missing capability check on multiple AJAX functions in the /core/core_ajax.php file in all versions up to, and including, 9.5.20. This makes it possible for authenticated attackers,...

Affected:
up to 10.0.1
Fixed in:
10.0.1
Disclosed:
Jun 6, 2024

CVE-2023-6966 on NVD →

The Moneytizer <= 9.6.3 - Cross-Site Request Forgery via multiple AJAX actions

high

The The Moneytizer plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 9.6.3. This is due to missing or incorrect nonce validation on multiple AJAX functions. This makes it possible for unauthenticated attackers to to update and retrieve billing and bank details, updat...

CVSS:
8.1
Affected:
up to 9.6.3
Fixed in:
10.0.1
Disclosed:
Jun 5, 2024

CVE-2023-6968 on NVD →

The Moneytizer <= 9.6.3 - Missing Authorization via multiple AJAX actions

high

The The Moneytizer plugin for WordPress is vulnerable to unauthorized access of data, modification of data, and loss of data due to a missing capability check on multiple AJAX functions in the /core/core_ajax.php file in all versions up to, and including, 9.6.3. This makes it possible for authenticated attackers, with...

CVSS:
8.1
Affected:
up to 9.6.3
Fixed in:
10.0.1
Disclosed:
Jun 5, 2024

CVE-2023-6966 on NVD →

The Moneytizer [the-moneytizer] < 9.6.1 (closed)

unknown

[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in The Moneytizer allows Stored XSS.This issue affects The Moneytizer: from n/a through 9.5.20.

Affected:
up to 9.6.1
Fixed in:
9.6.1
Disclosed:
Mar 21, 2024

CVE-2024-27990 on NVD →

The Moneytizer <= 9.5.20 - Authenticated (Contributor+) Stored Cross-Site Scripting

medium

The The Moneytizer plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 9.5.20 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages...

CVSS:
6.4
Affected:
up to 9.5.20
Fixed in:
9.6.1
Disclosed:
Mar 15, 2024

CVE-2024-27990 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database