WatchTowerHQ [watchtowerhq] <= 3.15.0 (unfixed)
unknown
[en] The WatchTowerHQ plugin for WordPress is vulnerable to arbitrary file read via the 'wht_download_big_object_origin' parameter in all versions up to, and including, 3.15.0. This is due to insufficient path validation in the handle_big_object_download_request function. This makes it possible for authenticated attack...
- Affected:
- up to 3.15.0
- Fix:
- No patched version reported
- Disclosed:
- Dec 12, 2025
CVE-2025-13972 on NVD →
WatchTowerHQ <= 3.16.0 - Authenticated (Administrator+) Arbitrary File Read via 'wht_download_big_object_origin' Parameter
medium
The WatchTowerHQ plugin for WordPress is vulnerable to arbitrary file read via the 'wht_download_big_object_origin' parameter in all versions up to, and including, 3.16.0. This is due to insufficient path validation in the handle_big_object_download_request function. This makes it possible for authenticated attackers,...
- CVSS:
- 4.9
- Affected:
- up to 3.16.0
- Fixed in:
- 3.16.1
- Disclosed:
- Dec 11, 2025
CVE-2025-13972 on NVD →
WatchTowerHQ [watchtowerhq] < 3.10.4
unknown
[en] The WatchTowerHQ plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 3.9.6. This is due to the 'watchtower_ota_token' default value is empty, and the not empty check is missing in the 'Password_Less_Access::login' function. This makes it possible for unauthenticated attack...
- Affected:
- up to 3.10.4
- Fixed in:
- 3.10.4
- Disclosed:
- Oct 26, 2024
CVE-2024-9933 on NVD →
WatchTowerHQ <= 3.10.1 - Authentication Bypass to Administrator due to Missing Empty Value Check
critical
The WatchTowerHQ plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 3.10.1. This is due to the 'watchtower_ota_token' default value is empty, and the not empty check is missing in the 'Password_Less_Access::login' function. This makes it possible for unauthenticated attackers...
- CVSS:
- 9.8
- Affected:
- up to 3.10.1
- Fixed in:
- 3.10.4
- Disclosed:
- Oct 25, 2024
CVE-2024-9933 on NVD →
WatchTowerHQ [watchtowerhq] < 3.6.17
unknown
[en] Improper Privilege Management vulnerability in WhatArmy WatchTowerHQ allows Privilege Escalation.This issue affects WatchTowerHQ: from n/a through 3.6.16.
- Affected:
- up to 3.6.17
- Fixed in:
- 3.6.17
- Disclosed:
- May 17, 2024
CVE-2023-25701 on NVD →
WatchTowerHQ <= 3.6.16 - Type Juggling to Authentication Bypass in check_ota
critical
The WatchTowerHQ plugin for WordPress is vulnerable to a type juggling issue in versions up to, and including, 3.6.16. This is due to an incorrect comparison in the check_ota function between the user-supplied access token and the configured WatchTower access token. This makes it possible for unauthenticated remote att...
- CVSS:
- 9.8
- Affected:
- up to 3.6.16
- Fixed in:
- 3.6.17
- Disclosed:
- Feb 14, 2023
CVE-2023-25701 on NVD →
WatchTowerHQ [watchtowerhq] < 3.6.16
unknown
[en] Unauth. Arbitrary File Download vulnerability in WatchTowerHQ plugin <= 3.6.15 on WordPress.
- Affected:
- up to 3.6.16
- Fixed in:
- 3.6.16
- Disclosed:
- Nov 18, 2022
CVE-2022-44583 on NVD →
WatchTowerHQ [watchtowerhq] < 3.6.16
unknown
[en] Unauth. Arbitrary File Deletion vulnerability in WatchTowerHQ plugin <= 3.6.15 on WordPress.
- Affected:
- up to 3.6.16
- Fixed in:
- 3.6.16
- Disclosed:
- Nov 18, 2022
CVE-2022-44584 on NVD →
WatchTowerHQ <= 3.6.15 - Unauthenticated Arbitrary File Deletion
critical
The WatchTowerHQ plugin for WordPress is vulnerable to arbitrary file deletion in versions up to, and including, 3.6.15 due to missing capability checks on several REST API endpoints. This makes it possible for unauthenticated attackers to delete arbitrary files on the affected site's server.
- CVSS:
- 9.1
- Affected:
- up to 3.6.15
- Fixed in:
- 3.6.16
- Disclosed:
- Nov 1, 2022
CVE-2022-44584 on NVD →
WatchTowerHQ <= 3.6.15 - Unauthenticated Arbitrary File Download
high
The WatchTowerHQ plugin for WordPress is vulnerable to arbitrary file downloads in versions up to, and including, 3.6.15 due to missing capability checks on several REST API endpoints. This makes it possible for unauthenticated attackers to download arbitrary files on the affected site's server leading to Information E...
- CVSS:
- 8.6
- Affected:
- up to 3.6.15
- Fixed in:
- 3.6.16
- Disclosed:
- Nov 1, 2022
CVE-2022-44583 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database