plugin

White Label Cms Vulnerabilities

17 known security issues reported for the White Label Cms WordPress plugin. Most recent disclosed Jul 10, 2026.

3 high 5 medium

Running White Label Cms on your site? Check whether your installed version is affected.

Scan your site free

White Label CMS <= 2.7.12 - Authenticated (Administrator+) Stored Cross-Site Scripting via Import Settings

medium

The White Label CMS plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 2.7.12 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject...

CVSS:
4.4
Affected:
up to 2.7.12
Fixed in:
2.7.13
Disclosed:
Jul 10, 2026

CVE-2026-11898 on NVD →

White Label CMS [white-label-cms] < 2.7.5

unknown

[en] Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in videousermanuals.Com White Label CMS allows Reflected XSS.This issue affects White Label CMS: from n/a through 2.7.4.

Affected:
up to 2.7.5
Fixed in:
2.7.5
Disclosed:
Aug 18, 2024

CVE-2024-43303 on NVD →

White Label CMS <= 2.7.4 - Reflected Cross-Site Scripting

medium

The White Label CMS plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 2.7.4 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully...

CVSS:
6.1
Affected:
up to 2.7.4
Fixed in:
2.7.5
Disclosed:
Aug 16, 2024

CVE-2024-43303 on NVD →

White Label CMS [white-label-cms] < 2.7.4

unknown

[en] The White Label CMS plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the reset_plugin function in all versions up to, and including, 2.7.3. This makes it possible for unauthenticated attackers to reset plugin settings.

Affected:
up to 2.7.4
Fixed in:
2.7.4
Disclosed:
May 10, 2024

CVE-2024-4280 on NVD →

White Label CMS <= 2.7.3 - Missing Authorization to Plugin Settings Reset

medium

The White Label CMS plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the reset_plugin function in all versions up to, and including, 2.7.3. This makes it possible for unauthenticated attackers to reset plugin settings.

CVSS:
5.3
Affected:
up to 2.7.3
Fixed in:
2.7.4
Disclosed:
May 9, 2024

CVE-2024-4280 on NVD →

White Label CMS [white-label-cms] < 2.5

unknown

[en] The White Label CMS WordPress plugin before 2.5 unserializes user input provided via the settings, which could allow high-privilege users such as admin to perform PHP Object Injection when a suitable gadget is present.

Affected:
up to 2.5
Fixed in:
2.5
Disclosed:
Jan 2, 2023

CVE-2022-4302 on NVD →

White Label CMS <= 2.4 - Authenticated (Administrator+) PHP Object Injection

high

The White Label CMS plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 2.4 via deserialization of untrusted input in the legacy_import function. This allows administrator-level attackers to inject a PHP Object. No POP chain is present in the vulnerable plugin. If a POP chain is...

CVSS:
7.2
Affected:
up to 2.4
Fixed in:
2.5
Disclosed:
Dec 8, 2022

CVE-2022-4302 on NVD →

White Label CMS [white-label-cms] < 2.2.9

unknown

[en] The White Label CMS WordPress plugin before 2.2.9 does not sanitise and validate the wlcms[_login_custom_js] parameter before outputting it back in the response while previewing, leading to a Reflected Cross-Site Scripting issue

Affected:
up to 2.2.9
Fixed in:
2.2.9
Disclosed:
Mar 7, 2022

CVE-2022-0422 on NVD →

White Label MS <= 2.2.8 - Reflected Cross-Site Scripting

medium

The White Label CMS WordPress plugin before 2.2.9 does not sanitise and validate the wlcms[_login_custom_js] parameter before outputting it back in the response while previewing, leading to a Reflected Cross-Site Scripting issue

CVSS:
6.1
Affected:
up to 2.2.9
Fixed in:
2.2.9
Disclosed:
Feb 7, 2022

CVE-2022-0422 on NVD →

White Label CMS [white-label-cms] < 1.5.3

unknown

Because of this vulnerability, the attackers can inject arbitrary JavaScript or HTML code. Update the plugin.

Affected:
up to 1.5.3
Fixed in:
1.5.3
Disclosed:
May 15, 2015

White Label CMS <= 1.5.2 - Cross-Site Request Forgery leading to Stored Cross-Site Scripting

medium

The White Label CMS plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.5.2. This is due to missing or incorrect nonce validation on the 'wlcmsImport' function. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execut...

CVSS:
4.7
Affected:
up to 1.5.3
Fixed in:
1.5.3
Disclosed:
Apr 29, 2015

White Label CMS [white-label-cms] < 1.5.3

unknown

The White Label CMS plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.5.2. This is due to missing or incorrect nonce validation on the 'wlcmsImport' function. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execut...

Affected:
up to 1.5.3
Fixed in:
1.5.3
Disclosed:
Apr 29, 2015

White Label CMS [white-label-cms] < 1.5.1

unknown

[en] Cross-site request forgery (CSRF) vulnerability in wlcms-plugin.php in the White Label CMS plugin before 1.5.1 for WordPress allows remote attackers to hijack the authentication of administrators for requests that modify the developer name via the wlcms_o_developer_name parameter in a save action to wp-admin/admin...

Affected:
up to 1.5.1
Fixed in:
1.5.1
Disclosed:
Oct 24, 2012

CVE-2012-5387 on NVD →

White Label CMS [white-label-cms] < 1.5.1

unknown

[en] Cross-site scripting (XSS) vulnerability in wlcms-plugin.php in the White Label CMS plugin 1.5 for WordPress allows remote authenticated administrators to inject arbitrary web script or HTML via the wlcms_o_developer_name parameter in a save action to wp-admin/admin.php, a related issue to CVE-2012-5387.

Affected:
up to 1.5.1
Fixed in:
1.5.1
Disclosed:
Oct 24, 2012

CVE-2012-5388 on NVD →

White Label CMS < 1.5.1 - Cross-Site Scripting

high

Cross-site scripting (XSS) vulnerability in wlcms-plugin.php in the White Label CMS plugin 1.5 for WordPress allows remote authenticated administrators to inject arbitrary web script or HTML via the wlcms_o_developer_name parameter in a save action to wp-admin/admin.php, a related issue to CVE-2012-5387.

CVSS:
7.1
Affected:
up to 1.5.1
Fixed in:
1.5.1
Disclosed:
Oct 21, 2012

CVE-2012-5388 on NVD →

White Label CMS < 1.5.1 - Reflected Cross-Site Scripting

high

Cross-site request forgery (CSRF) vulnerability in wlcms-plugin.php in the White Label CMS plugin before 1.5.1 for WordPress allows remote attackers to hijack the authentication of administrators for requests that modify the developer name via the wlcms_o_developer_name parameter in a save action to wp-admin/admin.php,...

CVSS:
7.1
Affected:
up to 1.5.1
Fixed in:
1.5.1
Disclosed:
Oct 21, 2012

CVE-2012-5387 on NVD →

White Label CMS [white-label-cms] < 1.5.3

unknown

Due to a lack of CSRF protection, and lack of sanitation of user input, it is possible to trigger a Persistent XSS attack via a CSRF attack. This attack targets in particular the Import functionality, which is located in the &#039;wlcmsImport&#039; function, within the file &#039;/white-label-cms/wlcms-plugin.php&#039;...

Affected:
up to 1.5.3
Fixed in:
1.5.3

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database