Verge3D Publishing and E-Commerce [verge3d] < 4.9.5
unknown
[en] Missing Authorization vulnerability in Soft8Soft LLC Verge3D allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Verge3D: from n/a through 4.9.4.
- Affected:
- up to 4.9.5
- Fixed in:
- 4.9.5
- Disclosed:
- Jun 6, 2025
CVE-2025-49268 on NVD →
Verge3D <= 4.9.4 - Missing Authorization
medium
The Verge3D Publishing and E-Commerce plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 4.9.4. This makes it possible for unauthenticated attackers to perform an unauthorized action.
- CVSS:
- 5.3
- Affected:
- up to 4.9.4
- Fixed in:
- 4.9.5
- Disclosed:
- Jun 5, 2025
CVE-2025-49268 on NVD →
Verge3D <= 4.9.3 - Reflected Cross-Site Scripting
medium
The Verge3D Publishing and E-Commerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and including, 4.9.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if...
- CVSS:
- 6.1
- Affected:
- up to 4.9.3
- Fixed in:
- 4.9.4
- Disclosed:
- May 29, 2025
CVE-2025-48241 on NVD →
Verge3D Publishing and E-Commerce [verge3d] < 4.9.4
unknown
[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Soft8Soft LLC Verge3D allows Reflected XSS. This issue affects Verge3D: from n/a through 4.9.3.
- Affected:
- up to 4.9.4
- Fixed in:
- 4.9.4
- Disclosed:
- May 23, 2025
CVE-2025-48241 on NVD →
Verge3D <= 4.9.0 - Cross-Site Request Forgery
medium
The Verge3D Publishing and E-Commerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 4.9.0. This is due to missing or incorrect nonce validation on a function. This makes it possible for unauthenticated attackers to perform an unauthorized action granted they can...
- CVSS:
- 4.3
- Affected:
- up to 4.9.0
- Fixed in:
- 4.9.3
- Disclosed:
- Apr 17, 2025
CVE-2025-39443 on NVD →
Verge3D Publishing and E-Commerce [verge3d] < 4.9.3
unknown
[en] Cross-Site Request Forgery (CSRF) vulnerability in Soft8Soft LLC Verge3D allows Cross Site Request Forgery. This issue affects Verge3D: from n/a through 4.9.0.
- Affected:
- up to 4.9.3
- Fixed in:
- 4.9.3
- Disclosed:
- Apr 17, 2025
CVE-2025-39443 on NVD →
Verge3D <= 4.8.2 - Cross-Site Request Forgery
medium
The Verge3D Publishing and E-Commerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 4.8.2. This is due to missing or incorrect nonce validation on a function. This makes it possible for unauthenticated attackers to perform an unauthorized action granted they can...
- CVSS:
- 4.3
- Affected:
- up to 4.8.2
- Fixed in:
- 4.8.3
- Disclosed:
- Mar 27, 2025
CVE-2025-30833 on NVD →
Verge3D Publishing and E-Commerce [verge3d] < 4.8.3
unknown
[en] Cross-Site Request Forgery (CSRF) vulnerability in Soft8Soft LLC Verge3D allows Cross Site Request Forgery. This issue affects Verge3D: from n/a through 4.8.2.
- Affected:
- up to 4.8.3
- Fixed in:
- 4.8.3
- Disclosed:
- Mar 27, 2025
CVE-2025-30833 on NVD →
Verge3D Publishing and E-Commerce [verge3d] < 4.8.1
unknown
[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Soft8Soft LLC Verge3D allows Reflected XSS. This issue affects Verge3D: from n/a through 4.8.0.
- Affected:
- up to 4.8.1
- Fixed in:
- 4.8.1
- Disclosed:
- Jan 21, 2025
CVE-2025-22709 on NVD →
Verge3D <= 4.8.0 - Reflected Cross-Site Scripting
medium
The Verge3D plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 4.8.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a...
- CVSS:
- 6.1
- Affected:
- up to 4.8.0
- Fixed in:
- 4.8.1
- Disclosed:
- Jan 15, 2025
CVE-2025-22709 on NVD →
Verge3D Publishing and E-Commerce [verge3d] < 4.5.3
unknown
[en] Improper Control of Generation of Code ('Code Injection') vulnerability in Soft8Soft LLC Verge3D Publishing and E-Commerce.This issue affects Verge3D Publishing and E-Commerce: from n/a through 4.5.2.
- Affected:
- up to 4.5.3
- Fixed in:
- 4.5.3
- Disclosed:
- Dec 29, 2023
CVE-2023-51420 on NVD →
Verge3D Publishing and E-Commerce [verge3d] < 4.5.3
unknown
[en] Unrestricted Upload of File with Dangerous Type vulnerability in Soft8Soft LLC Verge3D Publishing and E-Commerce.This issue affects Verge3D Publishing and E-Commerce: from n/a through 4.5.2.
- Affected:
- up to 4.5.3
- Fixed in:
- 4.5.3
- Disclosed:
- Dec 29, 2023
CVE-2023-51421 on NVD →
Verge3D <= 4.5.2 - Authenticated(Subscriber+) Arbitrary File Upload
high
The Verge3D Publishing and E-Commerce plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'v3d_upload_app_file' function in all versions up to, and including, 4.5.2. This makes it possible for authenticated attackers, with subscriber access and above, to upload arbitr...
- CVSS:
- 8.8
- Affected:
- up to 4.5.2
- Fixed in:
- 4.5.3
- Disclosed:
- Dec 27, 2023
CVE-2023-51421 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database