WordPress Popular Posts <= 7.1.0 - Unauthenticated Arbitrary Shortcode Execution
high
The The WordPress Popular Posts plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 7.1.0. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it possible for unauthenticated...
- CVSS:
- 7.3
- Affected:
- up to 7.1.0
- Fixed in:
- 7.2.0
- Disclosed:
- Jan 3, 2025
CVE-2024-11733 on NVD →
WP Popular Posts [wordpress-popular-posts] < 7.2.0
unknown
[en] The The WordPress Popular Posts plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 7.1.0. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it possible for unauthenti...
- Affected:
- up to 7.2.0
- Fixed in:
- 7.2.0
- Disclosed:
- Jan 3, 2025
CVE-2024-11733 on NVD →
WP Popular Posts [wordpress-popular-posts] < 6.3.3
unknown
[en] Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Hector Cabrera WordPress Popular Posts plugin <= 6.3.2 versions.
- Affected:
- up to 6.3.3
- Fixed in:
- 6.3.3
- Disclosed:
- Oct 18, 2023
CVE-2023-45607 on NVD →
WordPress Popular Posts <= 6.3.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode
medium
The WordPress Popular Posts plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in versions up to, and including, 6.3.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-...
- CVSS:
- 6.4
- Affected:
- up to 6.3.3
- Fixed in:
- 6.3.3
- Disclosed:
- Oct 6, 2023
CVE-2023-45607 on NVD →
WP Popular Posts [wordpress-popular-posts] < 6.3.3
unknown
The WordPress Popular Posts plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in versions up to, and including, 6.3.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-...
- Affected:
- up to 6.3.3
- Fixed in:
- 6.3.3
- Disclosed:
- Oct 6, 2023
WP Popular Posts [wordpress-popular-posts] < 6.1.0
unknown
[en] External initialization of trusted variables or data stores vulnerability exists in WordPress Popular Posts 6.0.5 and earlier, therefore the vulnerable product accepts untrusted external inputs to update certain internal variables. As a result, the number of views for an article may be manipulated through a crafte...
- Affected:
- up to 6.1.0
- Fixed in:
- 6.1.0
- Disclosed:
- Dec 7, 2022
CVE-2022-43468 on NVD →
WordPress Popular Posts <= 6.0.5 - Unauthenticated Views Changes
medium
The WordPress Popular Posts plugin for WordPress is vulnerable to Unauthenticated Views Changes in versions up to, and including, 6.0.5. This is due to a lack of user input validation on a REST endpoint that results in unprotected behavior in the 'update_views_count' function. This makes it possible for unauthenticated...
- CVSS:
- 5.3
- Affected:
- up to 6.0.5
- Fixed in:
- 6.1.0
- Disclosed:
- Nov 18, 2022
CVE-2022-43468 on NVD →
WP Popular Posts [wordpress-popular-posts] < 6.1.0
unknown
WordPress Plugin "WordPress Popular Posts" provided by Hector Cabrera accepts untrusted external inputs to update certain internal variables (CWE-454). Tsubasa Iinuma of Origami Systems reported this vulnerability to IPA. JPCERT/CC coordinated with the developer under Information Security Early Warning Partnership.
S...
- Affected:
- up to 6.1.0
- Fixed in:
- 6.1.0
- Disclosed:
- Nov 18, 2022
WordPress Popular Posts <= 5.5.1 - Reflected Cross-Site Scripting
medium
The WordPress Popular Posts plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in versions up to, and including, 5.5.1. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if...
- CVSS:
- 6.1
- Affected:
- up to 5.5.1
- Fixed in:
- 6.0.0
- Disclosed:
- Jun 29, 2022
WP Popular Posts [wordpress-popular-posts] < 6.0.0
unknown
Reflected Cross-Site Scripting (XSS) vulnerability discovered by WPScanTeam in WordPress WordPress Popular Posts plugin (versions <= 5.5.1)
Update the WordPress WordPress Popular Posts plugin to the latest available version (at least 6.0.0).
- Affected:
- up to 6.0.0
- Fixed in:
- 6.0.0
- Disclosed:
- Jun 29, 2022
WP Popular Posts [wordpress-popular-posts] < 6.0.0
unknown
The WordPress Popular Posts plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in versions up to, and including, 5.5.1. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if...
- Affected:
- up to 6.0.0
- Fixed in:
- 6.0.0
- Disclosed:
- Jun 29, 2022
WP Popular Posts [wordpress-popular-posts] < 5.3.3
unknown
[en] The WordPress Popular Posts WordPress plugin is vulnerable to arbitrary file uploads due to insufficient input file type validation found in the ~/src/Image.php file which makes it possible for attackers with contributor level access and above to upload malicious files that can be used to obtain remote code execut...
- Affected:
- up to 5.3.3
- Fixed in:
- 5.3.3
- Disclosed:
- Nov 17, 2021
CVE-2021-42362 on NVD →
WordPress Popular Posts <= 5.3.2 - Authenticated Arbitrary File Upload
high
The WordPress Popular Posts WordPress plugin is vulnerable to arbitrary file uploads due to insufficient input file type validation found in the ~/src/Image.php file which makes it possible for attackers with contributor level access and above to upload malicious files that can be used to obtain remote code execution,...
- CVSS:
- 8.8
- Affected:
- up to 5.3.2
- Fixed in:
- 5.3.3
- Disclosed:
- Nov 12, 2021
CVE-2021-42362 on NVD →
WP Popular Posts [wordpress-popular-posts] < 5.3.4
unknown
[en] Authenticated Persistent Cross-Site Scripting (XSS) vulnerability in WordPress Popular Posts plugin (versions <= 5.3.3). Vulnerable at &widget-wpp[2][post_type].
- Affected:
- up to 5.3.4
- Fixed in:
- 5.3.4
- Disclosed:
- Sep 23, 2021
CVE-2021-36872 on NVD →
WordPress Popular Posts <= 5.3.3 - Authenticated (Admin+) Stored Cross-Site Scripting
medium
Authenticated Persistent Cross-Site Scripting (XSS) vulnerability in WordPress Popular Posts plugin (versions <= 5.3.3). Vulnerable at &widget-wpp[2][post_type].
- CVSS:
- 5.5
- Affected:
- up to 5.3.3
- Fixed in:
- 5.3.4
- Disclosed:
- Jul 4, 2021
CVE-2021-36872 on NVD →
WP Popular Posts [wordpress-popular-posts] < 5.3.3
unknown
[en] Cross-site scripting vulnerability in WordPress Popular Posts 5.3.2 and earlier allows a remote authenticated attacker to inject an arbitrary script via unspecified vectors.
- Affected:
- up to 5.3.3
- Fixed in:
- 5.3.3
- Disclosed:
- Jun 28, 2021
CVE-2021-20746 on NVD →
WordPress Popular Posts <= 5.3.2 - Authenticated Cross-Site Scripting
medium
Cross-site scripting vulnerability in WordPress Popular Posts 5.3.2 and earlier allows a remote authenticated attacker to inject an arbitrary script via unspecified vectors.
- CVSS:
- 6.4
- Affected:
- up to 5.3.3
- Fixed in:
- 5.3.3
- Disclosed:
- Jun 23, 2021
CVE-2021-20746 on NVD →
WP Popular Posts [wordpress-popular-posts] < 5.3.3
unknown
Authenticated Stored Cross-Site Scripting (XSS) vulnerability discovered by Yu Iwama of Secure Sky Technology Inc. and the JPCERT/CC Vulnerability Coordination Group in WordPress Popular Posts plugin (versions <= 5.3.2).
- Affected:
- up to 5.3.3
- Fixed in:
- 5.3.3
- Disclosed:
- Jun 7, 2021
WP Popular Posts [wordpress-popular-posts] < 6.0.0
unknown
The plugin does not escape some URLs before outputting them back in attributes, leading to Reflected Cross-Site Scripting
- Affected:
- up to 6.0.0
- Fixed in:
- 6.0.0
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database