plugin

Web Stories Vulnerabilities

3 known security issues reported for the Web Stories WordPress plugin. Most recent disclosed Dec 11, 2024.

1 critical 2 medium

Running Web Stories on your site? Check whether your installed version is affected.

Scan your site free

Web Stories <= 1.37.0 - Authenticated (Contributor+) Stored Cross-Site Scripting

medium

The Web Stories plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.37.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages tha...

CVSS:
6.4
Affected:
up to 1.37.0
Fixed in:
1.38.0
Disclosed:
Dec 11, 2024

CVE-2024-54317 on NVD →

Web Stories for WordPress <= 1.31.0 - Insufficient Authorization

medium

The Web Stories for WordPress plugin for WordPress is vulnerable to authorization bypass in versions up to, and including, 1.31.0. This is due to insufficient authorization checks on the duplicate functionality. This makes it possible for authenticated attackers, with author-level permissions, to duplicate password pro...

CVSS:
4.3
Affected:
up to 1.32.0
Fixed in:
1.32.0
Disclosed:
May 8, 2023

CVE-2023-1979 on NVD →

Web Stories <= 1.24.0 - Server Side Request Forgery

critical

The Web Stories plugin for WordPress is vulnerable to Server-Side Request Forgery in versions up to, and including 1.24.0 due to insufficient validation of URLs supplied via the 'url' parameter found via the /v1/hotlink/proxy REST API Endpoint. This makes it possible for authenticated users to make web requests to arbi...

CVSS:
9.6
Affected:
up to 1.24.0
Fixed in:
1.25.0
Disclosed:
Oct 26, 2022

CVE-2022-3708 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database