WP Cerber Security, Anti-spam & Malware Scan [wp-cerber] < 9.5 (closed)
unknown
[en] The WP Cerber Security plugin for WordPress is vulnerable to IP Protection bypass in versions up to, and including 9.4 due to the plugin improperly checking for a visitor's IP address. This makes it possible for an attacker whose IP address has been blocked to bypass this control by setting the X-Forwarded-For: HT...
- Affected:
- up to 9.5
- Fixed in:
- 9.5
- Disclosed:
- Aug 31, 2024
CVE-2022-4100 on NVD →
WP Cerber Security <= 9.4 - IP Protection Bypass
medium
The WP Cerber Security plugin for WordPress is vulnerable to IP Protection bypass in versions up to, and including 9.4 due to the plugin improperly checking for a visitor's IP address. This makes it possible for an attacker whose IP address has been blocked to bypass this control by setting the X-Forwarded-For: HTTP he...
- CVSS:
- 5.3
- Affected:
- up to 9.4
- Fixed in:
- 9.5
- Disclosed:
- Aug 30, 2024
CVE-2022-4100 on NVD →
WP Cerber Security, Anti-spam & Malware Scan [wp-cerber] < 9.2 (closed)
unknown
[en] The WP Cerber Security plugin for WordPress is vulnerable to stored cross-site scripting via the log parameter when logging in to the site in versions up to, and including, 9.1. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses...
- Affected:
- up to 9.2
- Fixed in:
- 9.2
- Disclosed:
- Oct 20, 2023
CVE-2022-4712 on NVD →
WP Cerber Security <= 9.1 - Unauthenticated Stored Cross-Site Scripting
high
The WP Cerber Security plugin for WordPress is vulnerable to stored cross-site scripting via the log parameter when logging in to the site in versions up to, and including, 9.1. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an in...
- CVSS:
- 7.2
- Affected:
- up to 9.1
- Fixed in:
- 9.2
- Disclosed:
- Apr 19, 2023
CVE-2022-4712 on NVD →
WP Cerber Security, Anti-spam & Malware Scan [wp-cerber] < 9.3.3 (closed)
unknown
[en] The WP Cerber Security, Anti-spam & Malware Scan WordPress plugin before 9.3.3 does not properly block access to the REST API users endpoint when the blog is in a subdirectory, which could allow attackers to bypass the restriction in place and list users
- Affected:
- up to 9.3.3
- Fixed in:
- 9.3.3
- Disclosed:
- Jan 2, 2023
CVE-2022-4417 on NVD →
WP Cerber Security <= 9.3.2 - User Enumeration Bypass via REST API
medium
The WP Cerber Security plugin for WordPress is vulnerable to security protection bypass in versions up to, and including 9.3.2, that makes user enumeration possible via the REST API. This is due the plugin not blocking access to the user endpoint when the plugin resides within a subdirectory. This can be used by unauth...
- CVSS:
- 5.3
- Affected:
- up to 9.3.2
- Fixed in:
- 9.3.3
- Disclosed:
- Dec 12, 2022
CVE-2022-4417 on NVD →
WP Cerber Security, Anti-spam & Malware Scan [wp-cerber] < 9.1 (closed)
unknown
[en] The WP Cerber Security plugin for WordPress is vulnerable to security protection bypass in versions up to, and including 9.0, that makes user enumeration possible. This is due to improper validation on the value supplied through the 'author' parameter found in the ~/cerber-load.php file. In vulnerable versions, th...
- Affected:
- up to 9.1
- Fixed in:
- 9.1
- Disclosed:
- Sep 6, 2022
CVE-2022-2939 on NVD →
WP Cerber Security <= 9.0 - User Enumeration Bypass
medium
The WP Cerber Security plugin for WordPress is vulnerable to security protection bypass in versions up to, and including 9.0, that makes user enumeration possible. This is due to improper validation on the value supplied through the 'author' parameter found in the ~/cerber-load.php file. In vulnerable versions, the plu...
- CVSS:
- 5.3
- Affected:
- up to 9.0
- Fixed in:
- 9.1
- Disclosed:
- Sep 2, 2022
CVE-2022-2939 on NVD →
WP Cerber Security <= 9.0 - Authenticated (Admin+) Stored Cross-Site Scripting
medium
The WP Cerber Security plugin for WordPress is vulnerable to stored cross-site scripting via the 'add_acl_comment' parameter. This makes it possible for authenticated attackers with administrator-level permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
- CVSS:
- 5.5
- Affected:
- up to 9.0
- Fixed in:
- 9.1
- Disclosed:
- Aug 22, 2022
WP Cerber Security, Anti-spam & Malware Scan [wp-cerber] < 9.1 (closed)
unknown
The WP Cerber Security plugin for WordPress is vulnerable to stored cross-site scripting via the 'add_acl_comment' parameter. This makes it possible for authenticated attackers with administrator-level permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
- Affected:
- up to 9.1
- Fixed in:
- 9.1
- Disclosed:
- Aug 22, 2022
WP Cerber Security, Anti-spam & Malware Scan [wp-cerber] < 8.9.6 (closed)
unknown
[en] The WP Cerber Security, Anti-spam & Malware Scan WordPress plugin before 8.9.6 does not sanitise the $url variable before using it in an attribute in the Activity tab in the plugins dashboard, leading to an unauthenticated stored Cross-Site Scripting vulnerability.
- Affected:
- up to 8.9.6
- Fixed in:
- 8.9.6
- Disclosed:
- Mar 7, 2022
CVE-2022-0429 on NVD →
WP Cerber Security <= 8.9.5.2 - Unauthenticated Stored Cross-Site Scripting
high
The WP Cerber Security, Anti-spam & Malware Scan WordPress plugin before 8.9.6 does not sanitise the $url variable before using it in an attribute in the Activity tab in the plugins dashboard, leading to an unauthenticated stored Cross-Site Scripting vulnerability.
- CVSS:
- 7.2
- Affected:
- up to 8.9.5.2
- Fixed in:
- 8.9.6
- Disclosed:
- Feb 14, 2022
CVE-2022-0429 on NVD →
WP Cerber Security, Anti-spam & Malware Scan [wp-cerber] < 8.9.3 (closed)
unknown
[en] WP Cerber before 8.9.3 allows bypass of /wp-json access control via a trailing ? character.
- Affected:
- up to 8.9.3
- Fixed in:
- 8.9.3
- Disclosed:
- Aug 19, 2021
CVE-2021-37598 on NVD →
WP Cerber Security, Anti-spam & Malware Scan [wp-cerber] < 8.9.3 (closed)
unknown
[en] WP Cerber before 8.9.3 allows MFA bypass via wordpress_logged_in_[hash] manipulation.
- Affected:
- up to 8.9.3
- Fixed in:
- 8.9.3
- Disclosed:
- Aug 19, 2021
CVE-2021-37597 on NVD →
WP Cerber Security < 8.9.3 - Multifactor Bypass
critical
WP Cerber before 8.9.3 allows MFA bypass via wordpress_logged_in_[hash] manipulation.
- CVSS:
- 9.8
- Affected:
- up to 8.9.3
- Fixed in:
- 8.9.3
- Disclosed:
- Aug 16, 2021
CVE-2021-37597 on NVD →
WP Cerber < 8.9.3 - Access Bypass Control
medium
WP Cerber before 8.9.3 allows bypass of /wp-json access control via a trailing ? character.
- CVSS:
- 5.3
- Affected:
- up to 8.9.3
- Fixed in:
- 8.9.3
- Disclosed:
- Aug 16, 2021
CVE-2021-37598 on NVD →
WP Cerber Security, Anti-spam & Malware Scan [wp-cerber] < 2.7 (closed)
unknown
[en] The wp-cerber plugin before 2.7 for WordPress has XSS via the X-Forwarded-For HTTP header.
- Affected:
- up to 2.7
- Fixed in:
- 2.7
- Disclosed:
- Sep 17, 2019
CVE-2016-10990 on NVD →
WP Cerber Security, Anti-spam & Malware Scan [wp-cerber] < 2.9 (closed)
unknown
In version 2.7.2, WordPress Cerber Limit Login Attempts Plugin, doesn't check for a nonce.
Update the plugin.
- Affected:
- up to 2.9
- Fixed in:
- 2.9
- Disclosed:
- Aug 29, 2016
Cerber Security, Anti-spam & Malware Scan < 2.7 - Stored Cross-Site Scripting
high
The wp-cerber plugin before 2.7 for WordPress has XSS via the X-Forwarded-For HTTP header when "I'm behind a proxy" option is enabled.
- CVSS:
- 7.2
- Affected:
- up to 2.7
- Fixed in:
- 2.7
- Disclosed:
- Apr 1, 2016
CVE-2016-10990 on NVD →
WP Cerber Security, Anti-spam & Malware Scan [wp-cerber] < 2.0.1.7 (closed)
unknown
This WordPress plugin is prone to a cross-site scripting (XSS) vulnerability. It allows remote attackers to inject arbitrary script or HTML.
Update the plugin.
- Affected:
- up to 2.0.1.7
- Fixed in:
- 2.0.1.7
- Disclosed:
- Apr 1, 2016
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database