VK All in One Expansion Unit <= 9.113.3 - Authenticated (Contributor+) Stored Cross-Site Scripting
medium
The VK All in One Expansion Unit plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 9.113.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web sc...
- CVSS:
- 6.4
- Affected:
- up to 9.113.3
- Fixed in:
- 9.113.4
- Disclosed:
- Mar 23, 2026
CVE-2026-39483 on NVD →
VK All in One Expansion Unit [vk-all-in-one-expansion-unit] < 9.112.4
unknown
[en] The VK All in One Expansion Unit plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'vkExUnit_sns_title' parameter in all versions up to, and including, 9.112.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-le...
- Affected:
- up to 9.112.4
- Fixed in:
- 9.112.4
- Disclosed:
- Feb 18, 2026
CVE-2025-11737 on NVD →
VK All in One Expansion Unit <= 9.112.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via SNS Title
medium
The VK All in One Expansion Unit plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'vkExUnit_sns_title' parameter in all versions up to, and including, 9.112.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level a...
- CVSS:
- 6.4
- Affected:
- up to 9.112.3
- Fixed in:
- 9.112.4
- Disclosed:
- Feb 17, 2026
CVE-2025-11737 on NVD →
VK All in One Expansion Unit [vk-all-in-one-expansion-unit] < 9.112.2
unknown
[en] The VK All in One Expansion Unit plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'vkExUnit_cta_url' and 'vkExUnit_cta_button_text' parameters in all versions up to, and including, 9.112.1. This is due to a logic error in the CTA save function that reads sanitization callbacks from the wro...
- Affected:
- up to 9.112.2
- Fixed in:
- 9.112.2
- Disclosed:
- Nov 18, 2025
CVE-2025-11265 on NVD →
VK All in One Expansion Unit [vk-all-in-one-expansion-unit] < 9.112.2
unknown
[en] The VK All in One Expansion Unit plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the '_veu_custom_css' parameter in all versions up to, and including, 9.112.1. This is due to insufficient input sanitization and output escaping on the user-supplied Custom CSS value. This makes it possible for...
- Affected:
- up to 9.112.2
- Fixed in:
- 9.112.2
- Disclosed:
- Nov 18, 2025
CVE-2025-11267 on NVD →
VK All in One Expansion Unit <= 9.112.1 - Authenticated (Contributor+) Stored Cross-Site Scripting
medium
The VK All in One Expansion Unit plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the '_veu_custom_css' parameter in all versions up to, and including, 9.112.1. This is due to insufficient input sanitization and output escaping on the user-supplied Custom CSS value. This makes it possible for authe...
- CVSS:
- 6.4
- Affected:
- up to 9.112.1
- Fixed in:
- 9.112.2
- Disclosed:
- Nov 17, 2025
CVE-2025-11267 on NVD →
VK All in One Expansion Unit <= 9.112.1 - Authenticated (Contributor+) Stored Cross-Site Scripting
medium
The VK All in One Expansion Unit plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'vkExUnit_cta_url' and 'vkExUnit_cta_button_text' parameters in all versions up to, and including, 9.112.1. This is due to a logic error in the CTA save function that reads sanitization callbacks from the wrong va...
- CVSS:
- 6.4
- Affected:
- up to 9.112.1
- Fixed in:
- 9.112.2
- Disclosed:
- Nov 17, 2025
CVE-2025-11265 on NVD →
VK All in One Expansion Unit [vk-all-in-one-expansion-unit] < 9.100.1.0
unknown
[en] Cross-site scripting vulnerability exists in VK All in One Expansion Unit versions prior to 9.100.1.0. If this vulnerability is exploited, an arbitrary script may be executed on the web browser of the user who is accessing the web site using the product.
- Affected:
- up to 9.100.1.0
- Fixed in:
- 9.100.1.0
- Disclosed:
- Nov 13, 2024
CVE-2024-52268 on NVD →
VK All in One Expansion Unit [vk-all-in-one-expansion-unit] < 9.99.2.0
unknown
[en] Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Vektor,Inc. VK All in One Expansion Unit allows Stored XSS.This issue affects VK All in One Expansion Unit: from n/a through 9.99.1.0.
- Affected:
- up to 9.99.2.0
- Fixed in:
- 9.99.2.0
- Disclosed:
- Jul 20, 2024
CVE-2024-37956 on NVD →
VK All in One Expansion Unit <= 9.99.1.0 - Authenticated (Contributor+) Stored Cross-Site Scripting
medium
The VK All in One Expansion Unit plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 9.99.1.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web s...
- CVSS:
- 6.4
- Affected:
- up to 9.99.1.0
- Fixed in:
- 9.99.2.0
- Disclosed:
- Jul 10, 2024
CVE-2024-37956 on NVD →
VK All in One Expansion Unit [vk-all-in-one-expansion-unit] < 9.96.0.0
unknown
[en] The VK All in One Expansion Unit plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 9.95.0.1 via social meta tags. This makes it possible for unauthenticated attackers to view limited password protected content.
- Affected:
- up to 9.96.0.0
- Fixed in:
- 9.96.0.0
- Disclosed:
- Apr 9, 2024
CVE-2024-2093 on NVD →
VK All in One Expansion Unit <= 9.95.0.1 - Information Exposure
medium
The VK All in One Expansion Unit plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 9.95.0.1 via social meta tags. This makes it possible for unauthenticated attackers to view limited password protected content.
- CVSS:
- 6.5
- Affected:
- up to 9.95.0.1
- Fixed in:
- 9.96.0.0
- Disclosed:
- Mar 26, 2024
CVE-2024-2093 on NVD →
VK All in One Expansion Unit [vk-all-in-one-expansion-unit] < 9.97.0.0
unknown
[en] The VK All in One Expansion Unit plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the child page index widget in all versions up to, and including, 9.96.0.1 due to insufficient input sanitization and output escaping on user supplied attributes such as 'className.' This makes it possible for au...
- Affected:
- up to 9.97.0.0
- Fixed in:
- 9.97.0.0
- Disclosed:
- Mar 26, 2024
CVE-2024-2170 on NVD →
VK All in One Expansion Unit <= 9.96.0.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via className
medium
The VK All in One Expansion Unit plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the child page index widget in all versions up to, and including, 9.96.0.1 due to insufficient input sanitization and output escaping on user supplied attributes such as 'className.' This makes it possible for authent...
- CVSS:
- 6.4
- Affected:
- up to 9.96.0.1
- Fixed in:
- 9.97.0.0
- Disclosed:
- Mar 25, 2024
CVE-2024-2170 on NVD →
VK All in One Expansion Unit [vk-all-in-one-expansion-unit] < 9.88.2.0
unknown
[en] Cross-site scripting vulnerability in Profile setting function of VK All in One Expansion Unit 9.88.1.0 and earlier allows a remote authenticated attacker to inject an arbitrary script.
- Affected:
- up to 9.88.2.0
- Fixed in:
- 9.88.2.0
- Disclosed:
- May 23, 2023
CVE-2023-27926 on NVD →
VK All in One Expansion Unit [vk-all-in-one-expansion-unit] < 9.88.2.0
unknown
[en] Cross-site scripting vulnerability in CTA post function of VK All in One Expansion Unit 9.88.1.0 and earlier allows a remote authenticated attacker to inject an arbitrary script.
- Affected:
- up to 9.88.2.0
- Fixed in:
- 9.88.2.0
- Disclosed:
- May 23, 2023
CVE-2023-28367 on NVD →
VK All in One Expansion Unit [vk-all-in-one-expansion-unit] < 9.88.2.0
unknown
[en] Cross-site scripting vulnerability in Tag edit function of VK Blocks 1.53.0.1 and earlier and VK Blocks Pro 1.53.0.1 and earlier allows a remote authenticated attacker to inject an arbitrary script.
- Affected:
- up to 9.88.2.0
- Fixed in:
- 9.88.2.0
- Disclosed:
- May 23, 2023
CVE-2023-27923 on NVD →
VK All in One Expansion Unit <= 9.88.1.0 - Stored (Contributor+) Cross-Site Scripting in CTA Post
medium
The VK All in One Expansion Unit plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the CTA post functionality in versions up to, and including, 9.88.1.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level permissions...
- CVSS:
- 6.4
- Affected:
- up to 9.88.1.0
- Fixed in:
- 9.88.2.0
- Disclosed:
- May 9, 2023
CVE-2023-28367 on NVD →
VK All in One Expansion Unit <= 9.88.1.0 - Stored (Contributor+) Cross-Site Scripting in Profile Setting
medium
The VK All in One Expansion Unit plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Profile setting functionality in versions up to, and including, 9.88.1.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level permi...
- CVSS:
- 6.4
- Affected:
- up to 9.88.1.0
- Fixed in:
- 9.88.2.0
- Disclosed:
- May 9, 2023
CVE-2023-27926 on NVD →
VK All in One Expansion Unit [vk-all-in-one-expansion-unit] < 9.88.2.0
unknown
WordPress Plugin "VK Blocks" and "VK All in One Expansion Unit" provided by Vektor,Inc. contain multiple cross-site scripting vulnerabilities (CWE-79) listed below.<ul><li>Cross-site scripting vulnerability in Tag edit function - CVE-2023-27923</li><li>Cross-site scripting vulnerability in Post function - CVE-2023-2792...
- Affected:
- up to 9.88.2.0
- Fixed in:
- 9.88.2.0
- Disclosed:
- May 9, 2023
VK All in One Expansion Unit [vk-all-in-one-expansion-unit] < 9.87.1.0
unknown
[en] The VK All in One Expansion Unit WordPress plugin before 9.87.1.0 does not escape the $_SERVER['REQUEST_URI'] parameter before outputting it back in an attribute, which could lead to Reflected Cross-Site Scripting in old web browsers
- Affected:
- up to 9.87.1.0
- Fixed in:
- 9.87.1.0
- Disclosed:
- Mar 20, 2023
CVE-2023-0937 on NVD →
VK All in One Expansion Unit [vk-all-in-one-expansion-unit] < 9.86.0.0
unknown
[en] The VK All in One Expansion Unit WordPress plugin before 9.86.0.0 does not validate and escape some of its block options before outputting them back in a page/post where the block is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.
- Affected:
- up to 9.86.0.0
- Fixed in:
- 9.86.0.0
- Disclosed:
- Feb 27, 2023
CVE-2023-0230 on NVD →
VK All in One Expansion Unit [vk-all-in-one-expansion-unit] < 9.87.1.0
unknown
Update the WordPress VK All in One Expansion Unit plugin to the latest available version (at least 9.87.1.0).
WordFence discovered and reported this Cross Site Scripting (XSS) vulnerability in WordPress VK All in One Expansion Unit Plugin. This could allow a malicious actor to inject malicious scripts, such as redirect...
- Affected:
- up to 9.87.1.0
- Fixed in:
- 9.87.1.0
- Disclosed:
- Feb 23, 2023
VK All in One Expansion Unit <= 9.87.0.1 - Reflected Cross-Site Scripting via REQUEST_URI
medium
The VK All in One Expansion Unit plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘$_SERVER['REQUEST_URI']’ parameter in versions up to, and including, 9.87.0.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrar...
- CVSS:
- 4.7
- Affected:
- up to 9.87.0.1
- Fixed in:
- 9.87.1.0
- Disclosed:
- Feb 22, 2023
CVE-2023-0937 on NVD →
VK All in One Expansion Unit [vk-all-in-one-expansion-unit] < 9.87.1.0
unknown
The VK All in One Expansion Unit plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘$_SERVER['REQUEST_URI']’ parameter in versions up to, and including, 9.87.0.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrar...
- Affected:
- up to 9.87.1.0
- Fixed in:
- 9.87.1.0
- Disclosed:
- Feb 22, 2023
VK All in One Expansion Unit <= 9.85.0.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode
medium
The VK All in One Expansion Unit plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in versions up to, and including, 9.85.0.1 due to insufficient input sanitization and output escaping on user supplied attributes such as class_name. This makes it possible for authenticated...
- CVSS:
- 6.4
- Affected:
- up to 9.85.0.1
- Fixed in:
- 9.86.0.0
- Disclosed:
- Feb 3, 2023
CVE-2023-0230 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database