WHMCS Bridge <= 6.9 - Unauthenticated Arbitrary File Upload via 'ccce' Parameter
high
The WHMCS Bridge plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the connect() function in all versions up to, and including, 6.9. This makes it possible for authenticated attackers, with Custom-level access and above, to upload arbitrary files on the affected site's...
- CVSS:
- 8.8
- Affected:
- up to 6.9
- Fix:
- No patched version reported
- Disclosed:
- Jul 7, 2026
CVE-2026-14489 on NVD →
WHMCS Bridge [whmcs-bridge] < 6.4b
unknown
[en] The WHMCS Bridge WordPress plugin before 6.4b does not sanitise and escape the error parameter before outputting it back in admin dashboard, leading to a Reflected Cross-Site Scripting
- Affected:
- up to 6.4b
- Fixed in:
- 6.4b
- Disclosed:
- Feb 28, 2022
CVE-2021-25112 on NVD →
WHMCS Bridge <= 6.3 - Reflected Cross-Site Scripting
medium
The WHMCS Bridge WordPress plugin before 6.4b does not sanitise and escape the error parameter before outputting it back in admin dashboard, leading to a Reflected Cross-Site Scripting
- CVSS:
- 6.1
- Affected:
- up to 6.3
- Fixed in:
- 6.4b
- Disclosed:
- Jan 27, 2022
CVE-2021-25112 on NVD →
WHMCS Bridge [whmcs-bridge] < 6.3
unknown
[en] The WHMCS Bridge WordPress plugin is vulnerable to Stored Cross-Site Scripting via the cc_whmcs_bridge_url parameter found in the ~/whmcs-bridge/bridge_cp.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 6.1. Due to missing authorization checks on the cc_whmcs_bridge...
- Affected:
- up to 6.3
- Fixed in:
- 6.3
- Disclosed:
- Jan 18, 2022
CVE-2021-4074 on NVD →
WHMCS Bridge <= 6.1 Subscriber+ Stored Cross-Site Scripting
medium
The WHMCS Bridge WordPress plugin is vulnerable to Stored Cross-Site Scripting via the cc_whmcs_bridge_url parameter found in the ~/whmcs-bridge/bridge_cp.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 6.1. Due to missing authorization checks on the cc_whmcs_bridge_add_...
- CVSS:
- 6.4
- Affected:
- up to 6.1
- Fixed in:
- 6.3
- Disclosed:
- Jan 14, 2022
CVE-2021-4074 on NVD →
WHMCS Bridge [whmcs-bridge] < 6.3
unknown
Authenticated Arbitrary Plugin Settings Change vulnerability discovered in WordPress WHMCS Bridge plugin (versions <= 6.1).
- Affected:
- up to 6.3
- Fixed in:
- 6.3
- Disclosed:
- Jan 5, 2022
WHMCS Bridge [whmcs-bridge] < 6.3
unknown
Cross-Site Request Forgery (CSRF) vulnerability discovered in WordPress WHMCS Bridge plugin (versions <= 6.1).
- Affected:
- up to 6.3
- Fixed in:
- 6.3
- Disclosed:
- Jan 5, 2022
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database