plugin

Whmcs Bridge Vulnerabilities

7 known security issues reported for the Whmcs Bridge WordPress plugin. Most recent disclosed Jul 7, 2026.

1 high 2 medium

Running Whmcs Bridge on your site? Check whether your installed version is affected.

Scan your site free

WHMCS Bridge <= 6.9 - Unauthenticated Arbitrary File Upload via 'ccce' Parameter

high

The WHMCS Bridge plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the connect() function in all versions up to, and including, 6.9. This makes it possible for authenticated attackers, with Custom-level access and above, to upload arbitrary files on the affected site's...

CVSS:
8.8
Affected:
up to 6.9
Fix:
No patched version reported
Disclosed:
Jul 7, 2026

CVE-2026-14489 on NVD →

WHMCS Bridge [whmcs-bridge] < 6.4b

unknown

[en] The WHMCS Bridge WordPress plugin before 6.4b does not sanitise and escape the error parameter before outputting it back in admin dashboard, leading to a Reflected Cross-Site Scripting

Affected:
up to 6.4b
Fixed in:
6.4b
Disclosed:
Feb 28, 2022

CVE-2021-25112 on NVD →

WHMCS Bridge <= 6.3 - Reflected Cross-Site Scripting

medium

The WHMCS Bridge WordPress plugin before 6.4b does not sanitise and escape the error parameter before outputting it back in admin dashboard, leading to a Reflected Cross-Site Scripting

CVSS:
6.1
Affected:
up to 6.3
Fixed in:
6.4b
Disclosed:
Jan 27, 2022

CVE-2021-25112 on NVD →

WHMCS Bridge [whmcs-bridge] < 6.3

unknown

[en] The WHMCS Bridge WordPress plugin is vulnerable to Stored Cross-Site Scripting via the cc_whmcs_bridge_url parameter found in the ~/whmcs-bridge/bridge_cp.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 6.1. Due to missing authorization checks on the cc_whmcs_bridge...

Affected:
up to 6.3
Fixed in:
6.3
Disclosed:
Jan 18, 2022

CVE-2021-4074 on NVD →

WHMCS Bridge <= 6.1 Subscriber+ Stored Cross-Site Scripting

medium

The WHMCS Bridge WordPress plugin is vulnerable to Stored Cross-Site Scripting via the cc_whmcs_bridge_url parameter found in the ~/whmcs-bridge/bridge_cp.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 6.1. Due to missing authorization checks on the cc_whmcs_bridge_add_...

CVSS:
6.4
Affected:
up to 6.1
Fixed in:
6.3
Disclosed:
Jan 14, 2022

CVE-2021-4074 on NVD →

WHMCS Bridge [whmcs-bridge] < 6.3

unknown

Authenticated Arbitrary Plugin Settings Change vulnerability discovered in WordPress WHMCS Bridge plugin (versions <= 6.1).

Affected:
up to 6.3
Fixed in:
6.3
Disclosed:
Jan 5, 2022

WHMCS Bridge [whmcs-bridge] < 6.3

unknown

Cross-Site Request Forgery (CSRF) vulnerability discovered in WordPress WHMCS Bridge plugin (versions <= 6.1).

Affected:
up to 6.3
Fixed in:
6.3
Disclosed:
Jan 5, 2022

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database