WappPress – Create Mobile App for any WordPress site with our Flutter Mobile App Builder in just 1 minute [wapppress-builds-android-app-for-website] < 6.0.5
unknown
[en] Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in WappPress Team WappPress allows Stored XSS.This issue affects WappPress: from n/a through 6.0.4.
- Affected:
- up to 6.0.5
- Fixed in:
- 6.0.5
- Disclosed:
- Aug 12, 2024
CVE-2024-43137 on NVD →
WappPress <= 6.0.4 - Authenticated (Administrator+) Stored Cross-Site Scripting
medium
The WappPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versions up to, and including, 6.0.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level access and above, to inject arbitrary web sc...
- CVSS:
- 4.4
- Affected:
- up to 6.0.4
- Fixed in:
- 6.0.5
- Disclosed:
- Aug 7, 2024
CVE-2024-43137 on NVD →
WappPress – Create Mobile App for any WordPress site with our Flutter Mobile App Builder in just 1 minute [wapppress-builds-android-app-for-website] < 6.0.5
unknown
[en] Server-Side Request Forgery (SSRF) vulnerability in WappPress Team WappPress.This issue affects WappPress: from n/a through 6.0.4.
- Affected:
- up to 6.0.5
- Fixed in:
- 6.0.5
- Disclosed:
- Jul 20, 2024
CVE-2024-38758 on NVD →
WappPress <= 6.0.4 - Authenticated (Subscriber+) Server-Side Request Forgery
medium
The WappPress – Create Mobile App for any WordPress site with our Mobile App Builder in just 1 minute plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 6.0.4. This makes it possible for authenticated attackers, with Subscriber-level access and above, to make web req...
- CVSS:
- 6.4
- Affected:
- up to 6.0.4
- Fixed in:
- 6.0.5
- Disclosed:
- Jul 11, 2024
CVE-2024-38758 on NVD →
WappPress – Create Mobile App for any WordPress site with our Flutter Mobile App Builder in just 1 minute [wapppress-builds-android-app-for-website] < 6.0.0
unknown
[en] Unrestricted Upload of File with Dangerous Type vulnerability in WappPress Team WappPress.This issue affects WappPress: from n/a through 5.0.3.
- Affected:
- up to 6.0.0
- Fixed in:
- 6.0.0
- Disclosed:
- Mar 27, 2024
CVE-2023-49815 on NVD →
WappPress <= 5.0.3 - Unauthenticated Arbitrary File Upload
critical
The WappPress – Create Mobile App for any WordPress site with our Mobile App Builder in just 1 minute plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in all versions up to, and including, 5.0.3. This makes it possible for unauthenticated attackers to upload arbitrary fil...
- CVSS:
- 9.8
- Affected:
- up to 5.0.3
- Fixed in:
- 6.0.0
- Disclosed:
- Dec 5, 2023
CVE-2023-49815 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database