The Moneytizer <= 10.0.10 - Missing Authorization
medium
The The Moneytizer plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 10.0.10. This makes it possible for unauthenticated attackers to perform an unauthorized action.
- CVSS:
- 5.3
- Affected:
- up to 10.0.10
- Fix:
- No patched version reported
- Disclosed:
- Feb 22, 2026
CVE-2026-39685 on NVD →
The Moneytizer <= 10.0.9 - Authenticated (Contributor+) Stored Cross-Site Scripting
medium
The The Moneytizer plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 10.0.9 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages...
- CVSS:
- 6.4
- Affected:
- up to 10.0.9
- Fixed in:
- 10.0.10
- Disclosed:
- Dec 31, 2025
CVE-2025-62756 on NVD →
The Moneytizer [the-moneytizer] <= 10.0.6 (unfixed)
unknown
[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in lvaudore The Moneytizer allows DOM-Based XSS.This issue affects The Moneytizer: from n/a through 10.0.6.
- Affected:
- up to 10.0.6
- Fix:
- No patched version reported
- Disclosed:
- Dec 31, 2025
CVE-2025-62756 on NVD →
The Moneytizer [the-moneytizer] < 10.0.1 (closed)
unknown
[en] The The Moneytizer plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 9.5.20. This is due to missing or incorrect nonce validation on multiple AJAX functions. This makes it possible for unauthenticated attackers to to update and retrieve billing and bank details,...
- Affected:
- up to 10.0.1
- Fixed in:
- 10.0.1
- Disclosed:
- Jun 6, 2024
CVE-2023-6968 on NVD →
The Moneytizer [the-moneytizer] < 10.0.1 (closed)
unknown
[en] The The Moneytizer plugin for WordPress is vulnerable to unauthorized access of data, modification of data, and loss of data due to a missing capability check on multiple AJAX functions in the /core/core_ajax.php file in all versions up to, and including, 9.5.20. This makes it possible for authenticated attackers,...
- Affected:
- up to 10.0.1
- Fixed in:
- 10.0.1
- Disclosed:
- Jun 6, 2024
CVE-2023-6966 on NVD →
The Moneytizer <= 9.6.3 - Cross-Site Request Forgery via multiple AJAX actions
high
The The Moneytizer plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 9.6.3. This is due to missing or incorrect nonce validation on multiple AJAX functions. This makes it possible for unauthenticated attackers to to update and retrieve billing and bank details, updat...
- CVSS:
- 8.1
- Affected:
- up to 9.6.3
- Fixed in:
- 10.0.1
- Disclosed:
- Jun 5, 2024
CVE-2023-6968 on NVD →
The Moneytizer <= 9.6.3 - Missing Authorization via multiple AJAX actions
high
The The Moneytizer plugin for WordPress is vulnerable to unauthorized access of data, modification of data, and loss of data due to a missing capability check on multiple AJAX functions in the /core/core_ajax.php file in all versions up to, and including, 9.6.3. This makes it possible for authenticated attackers, with...
- CVSS:
- 8.1
- Affected:
- up to 9.6.3
- Fixed in:
- 10.0.1
- Disclosed:
- Jun 5, 2024
CVE-2023-6966 on NVD →
The Moneytizer [the-moneytizer] < 9.6.1 (closed)
unknown
[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in The Moneytizer allows Stored XSS.This issue affects The Moneytizer: from n/a through 9.5.20.
- Affected:
- up to 9.6.1
- Fixed in:
- 9.6.1
- Disclosed:
- Mar 21, 2024
CVE-2024-27990 on NVD →
The Moneytizer <= 9.5.20 - Authenticated (Contributor+) Stored Cross-Site Scripting
medium
The The Moneytizer plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 9.5.20 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages...
- CVSS:
- 6.4
- Affected:
- up to 9.5.20
- Fixed in:
- 9.6.1
- Disclosed:
- Mar 15, 2024
CVE-2024-27990 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database