plugin

Watchtowerhq Vulnerabilities

10 known security issues reported for the Watchtowerhq WordPress plugin. Most recent disclosed Dec 12, 2025.

3 critical 1 high 1 medium

Running Watchtowerhq on your site? Check whether your installed version is affected.

Scan your site free

WatchTowerHQ [watchtowerhq] <= 3.15.0 (unfixed)

unknown

[en] The WatchTowerHQ plugin for WordPress is vulnerable to arbitrary file read via the 'wht_download_big_object_origin' parameter in all versions up to, and including, 3.15.0. This is due to insufficient path validation in the handle_big_object_download_request function. This makes it possible for authenticated attack...

Affected:
up to 3.15.0
Fix:
No patched version reported
Disclosed:
Dec 12, 2025

CVE-2025-13972 on NVD →

WatchTowerHQ <= 3.16.0 - Authenticated (Administrator+) Arbitrary File Read via 'wht_download_big_object_origin' Parameter

medium

The WatchTowerHQ plugin for WordPress is vulnerable to arbitrary file read via the 'wht_download_big_object_origin' parameter in all versions up to, and including, 3.16.0. This is due to insufficient path validation in the handle_big_object_download_request function. This makes it possible for authenticated attackers,...

CVSS:
4.9
Affected:
up to 3.16.0
Fixed in:
3.16.1
Disclosed:
Dec 11, 2025

CVE-2025-13972 on NVD →

WatchTowerHQ [watchtowerhq] < 3.10.4

unknown

[en] The WatchTowerHQ plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 3.9.6. This is due to the 'watchtower_ota_token' default value is empty, and the not empty check is missing in the 'Password_Less_Access::login' function. This makes it possible for unauthenticated attack...

Affected:
up to 3.10.4
Fixed in:
3.10.4
Disclosed:
Oct 26, 2024

CVE-2024-9933 on NVD →

WatchTowerHQ <= 3.10.1 - Authentication Bypass to Administrator due to Missing Empty Value Check

critical

The WatchTowerHQ plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 3.10.1. This is due to the 'watchtower_ota_token' default value is empty, and the not empty check is missing in the 'Password_Less_Access::login' function. This makes it possible for unauthenticated attackers...

CVSS:
9.8
Affected:
up to 3.10.1
Fixed in:
3.10.4
Disclosed:
Oct 25, 2024

CVE-2024-9933 on NVD →

WatchTowerHQ [watchtowerhq] < 3.6.17

unknown

[en] Improper Privilege Management vulnerability in WhatArmy WatchTowerHQ allows Privilege Escalation.This issue affects WatchTowerHQ: from n/a through 3.6.16.

Affected:
up to 3.6.17
Fixed in:
3.6.17
Disclosed:
May 17, 2024

CVE-2023-25701 on NVD →

WatchTowerHQ <= 3.6.16 - Type Juggling to Authentication Bypass in check_ota

critical

The WatchTowerHQ plugin for WordPress is vulnerable to a type juggling issue in versions up to, and including, 3.6.16. This is due to an incorrect comparison in the check_ota function between the user-supplied access token and the configured WatchTower access token. This makes it possible for unauthenticated remote att...

CVSS:
9.8
Affected:
up to 3.6.16
Fixed in:
3.6.17
Disclosed:
Feb 14, 2023

CVE-2023-25701 on NVD →

WatchTowerHQ [watchtowerhq] < 3.6.16

unknown

[en] Unauth. Arbitrary File Download vulnerability in WatchTowerHQ plugin <= 3.6.15 on WordPress.

Affected:
up to 3.6.16
Fixed in:
3.6.16
Disclosed:
Nov 18, 2022

CVE-2022-44583 on NVD →

WatchTowerHQ [watchtowerhq] < 3.6.16

unknown

[en] Unauth. Arbitrary File Deletion vulnerability in WatchTowerHQ plugin <= 3.6.15 on WordPress.

Affected:
up to 3.6.16
Fixed in:
3.6.16
Disclosed:
Nov 18, 2022

CVE-2022-44584 on NVD →

WatchTowerHQ <= 3.6.15 - Unauthenticated Arbitrary File Deletion

critical

The WatchTowerHQ plugin for WordPress is vulnerable to arbitrary file deletion in versions up to, and including, 3.6.15 due to missing capability checks on several REST API endpoints. This makes it possible for unauthenticated attackers to delete arbitrary files on the affected site's server.

CVSS:
9.1
Affected:
up to 3.6.15
Fixed in:
3.6.16
Disclosed:
Nov 1, 2022

CVE-2022-44584 on NVD →

WatchTowerHQ <= 3.6.15 - Unauthenticated Arbitrary File Download

high

The WatchTowerHQ plugin for WordPress is vulnerable to arbitrary file downloads in versions up to, and including, 3.6.15 due to missing capability checks on several REST API endpoints. This makes it possible for unauthenticated attackers to download arbitrary files on the affected site's server leading to Information E...

CVSS:
8.6
Affected:
up to 3.6.15
Fixed in:
3.6.16
Disclosed:
Nov 1, 2022

CVE-2022-44583 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database