plugin

Wp Cerber Vulnerabilities

20 known security issues reported for the Wp Cerber WordPress plugin. Most recent disclosed Aug 31, 2024.

1 critical 3 high 5 medium

Running Wp Cerber on your site? Check whether your installed version is affected.

Scan your site free

WP Cerber Security, Anti-spam &amp; Malware Scan [wp-cerber] < 9.5 (closed)

unknown

[en] The WP Cerber Security plugin for WordPress is vulnerable to IP Protection bypass in versions up to, and including 9.4 due to the plugin improperly checking for a visitor's IP address. This makes it possible for an attacker whose IP address has been blocked to bypass this control by setting the X-Forwarded-For: HT...

Affected:
up to 9.5
Fixed in:
9.5
Disclosed:
Aug 31, 2024

CVE-2022-4100 on NVD →

WP Cerber Security <= 9.4 - IP Protection Bypass

medium

The WP Cerber Security plugin for WordPress is vulnerable to IP Protection bypass in versions up to, and including 9.4 due to the plugin improperly checking for a visitor's IP address. This makes it possible for an attacker whose IP address has been blocked to bypass this control by setting the X-Forwarded-For: HTTP he...

CVSS:
5.3
Affected:
up to 9.4
Fixed in:
9.5
Disclosed:
Aug 30, 2024

CVE-2022-4100 on NVD →

WP Cerber Security, Anti-spam &amp; Malware Scan [wp-cerber] < 9.2 (closed)

unknown

[en] The WP Cerber Security plugin for WordPress is vulnerable to stored cross-site scripting via the log parameter when logging in to the site in versions up to, and including, 9.1. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses...

Affected:
up to 9.2
Fixed in:
9.2
Disclosed:
Oct 20, 2023

CVE-2022-4712 on NVD →

WP Cerber Security <= 9.1 - Unauthenticated Stored Cross-Site Scripting

high

The WP Cerber Security plugin for WordPress is vulnerable to stored cross-site scripting via the log parameter when logging in to the site in versions up to, and including, 9.1. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an in...

CVSS:
7.2
Affected:
up to 9.1
Fixed in:
9.2
Disclosed:
Apr 19, 2023

CVE-2022-4712 on NVD →

WP Cerber Security, Anti-spam &amp; Malware Scan [wp-cerber] < 9.3.3 (closed)

unknown

[en] The WP Cerber Security, Anti-spam & Malware Scan WordPress plugin before 9.3.3 does not properly block access to the REST API users endpoint when the blog is in a subdirectory, which could allow attackers to bypass the restriction in place and list users

Affected:
up to 9.3.3
Fixed in:
9.3.3
Disclosed:
Jan 2, 2023

CVE-2022-4417 on NVD →

WP Cerber Security <= 9.3.2 - User Enumeration Bypass via REST API

medium

The WP Cerber Security plugin for WordPress is vulnerable to security protection bypass in versions up to, and including 9.3.2, that makes user enumeration possible via the REST API. This is due the plugin not blocking access to the user endpoint when the plugin resides within a subdirectory. This can be used by unauth...

CVSS:
5.3
Affected:
up to 9.3.2
Fixed in:
9.3.3
Disclosed:
Dec 12, 2022

CVE-2022-4417 on NVD →

WP Cerber Security, Anti-spam &amp; Malware Scan [wp-cerber] < 9.1 (closed)

unknown

[en] The WP Cerber Security plugin for WordPress is vulnerable to security protection bypass in versions up to, and including 9.0, that makes user enumeration possible. This is due to improper validation on the value supplied through the 'author' parameter found in the ~/cerber-load.php file. In vulnerable versions, th...

Affected:
up to 9.1
Fixed in:
9.1
Disclosed:
Sep 6, 2022

CVE-2022-2939 on NVD →

WP Cerber Security <= 9.0 - User Enumeration Bypass

medium

The WP Cerber Security plugin for WordPress is vulnerable to security protection bypass in versions up to, and including 9.0, that makes user enumeration possible. This is due to improper validation on the value supplied through the 'author' parameter found in the ~/cerber-load.php file. In vulnerable versions, the plu...

CVSS:
5.3
Affected:
up to 9.0
Fixed in:
9.1
Disclosed:
Sep 2, 2022

CVE-2022-2939 on NVD →

WP Cerber Security <= 9.0 - Authenticated (Admin+) Stored Cross-Site Scripting

medium

The WP Cerber Security plugin for WordPress is vulnerable to stored cross-site scripting via the 'add_acl_comment' parameter. This makes it possible for authenticated attackers with administrator-level permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

CVSS:
5.5
Affected:
up to 9.0
Fixed in:
9.1
Disclosed:
Aug 22, 2022

WP Cerber Security, Anti-spam &amp; Malware Scan [wp-cerber] < 9.1 (closed)

unknown

The WP Cerber Security plugin for WordPress is vulnerable to stored cross-site scripting via the 'add_acl_comment' parameter. This makes it possible for authenticated attackers with administrator-level permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

Affected:
up to 9.1
Fixed in:
9.1
Disclosed:
Aug 22, 2022

WP Cerber Security, Anti-spam &amp; Malware Scan [wp-cerber] < 8.9.6 (closed)

unknown

[en] The WP Cerber Security, Anti-spam & Malware Scan WordPress plugin before 8.9.6 does not sanitise the $url variable before using it in an attribute in the Activity tab in the plugins dashboard, leading to an unauthenticated stored Cross-Site Scripting vulnerability.

Affected:
up to 8.9.6
Fixed in:
8.9.6
Disclosed:
Mar 7, 2022

CVE-2022-0429 on NVD →

WP Cerber Security <= 8.9.5.2 - Unauthenticated Stored Cross-Site Scripting

high

The WP Cerber Security, Anti-spam & Malware Scan WordPress plugin before 8.9.6 does not sanitise the $url variable before using it in an attribute in the Activity tab in the plugins dashboard, leading to an unauthenticated stored Cross-Site Scripting vulnerability.

CVSS:
7.2
Affected:
up to 8.9.5.2
Fixed in:
8.9.6
Disclosed:
Feb 14, 2022

CVE-2022-0429 on NVD →

WP Cerber Security, Anti-spam &amp; Malware Scan [wp-cerber] < 8.9.3 (closed)

unknown

[en] WP Cerber before 8.9.3 allows bypass of /wp-json access control via a trailing ? character.

Affected:
up to 8.9.3
Fixed in:
8.9.3
Disclosed:
Aug 19, 2021

CVE-2021-37598 on NVD →

WP Cerber Security, Anti-spam &amp; Malware Scan [wp-cerber] < 8.9.3 (closed)

unknown

[en] WP Cerber before 8.9.3 allows MFA bypass via wordpress_logged_in_[hash] manipulation.

Affected:
up to 8.9.3
Fixed in:
8.9.3
Disclosed:
Aug 19, 2021

CVE-2021-37597 on NVD →

WP Cerber Security < 8.9.3 - Multifactor Bypass

critical

WP Cerber before 8.9.3 allows MFA bypass via wordpress_logged_in_[hash] manipulation.

CVSS:
9.8
Affected:
up to 8.9.3
Fixed in:
8.9.3
Disclosed:
Aug 16, 2021

CVE-2021-37597 on NVD →

WP Cerber < 8.9.3 - Access Bypass Control

medium

WP Cerber before 8.9.3 allows bypass of /wp-json access control via a trailing ? character.

CVSS:
5.3
Affected:
up to 8.9.3
Fixed in:
8.9.3
Disclosed:
Aug 16, 2021

CVE-2021-37598 on NVD →

WP Cerber Security, Anti-spam &amp; Malware Scan [wp-cerber] < 2.7 (closed)

unknown

[en] The wp-cerber plugin before 2.7 for WordPress has XSS via the X-Forwarded-For HTTP header.

Affected:
up to 2.7
Fixed in:
2.7
Disclosed:
Sep 17, 2019

CVE-2016-10990 on NVD →

WP Cerber Security, Anti-spam &amp; Malware Scan [wp-cerber] < 2.9 (closed)

unknown

In version 2.7.2, WordPress Cerber Limit Login Attempts Plugin, doesn't check for a nonce. Update the plugin.

Affected:
up to 2.9
Fixed in:
2.9
Disclosed:
Aug 29, 2016

Cerber Security, Anti-spam & Malware Scan < 2.7 - Stored Cross-Site Scripting

high

The wp-cerber plugin before 2.7 for WordPress has XSS via the X-Forwarded-For HTTP header when "I'm behind a proxy" option is enabled.

CVSS:
7.2
Affected:
up to 2.7
Fixed in:
2.7
Disclosed:
Apr 1, 2016

CVE-2016-10990 on NVD →

WP Cerber Security, Anti-spam &amp; Malware Scan [wp-cerber] < 2.0.1.7 (closed)

unknown

This WordPress plugin is prone to a cross-site scripting (XSS) vulnerability. It allows remote attackers to inject arbitrary script or HTML. Update the plugin.

Affected:
up to 2.0.1.7
Fixed in:
2.0.1.7
Disclosed:
Apr 1, 2016

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database