plugin

Wp Discord Invite Vulnerabilities

4 known security issues reported for the Wp Discord Invite WordPress plugin. Most recent disclosed May 7, 2025.

4 medium

Running Wp Discord Invite on your site? Check whether your installed version is affected.

Scan your site free

WP Discord Invite <= 2.5.3 - Authenticated (Administrator+) Stored Cross-Site Scripting

medium

The WP Discord Invite plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.5.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level access and above, to inject arbitrary web scripts in pa...

CVSS:
4.4
Affected:
up to 2.5.3
Fixed in:
2.6.0
Disclosed:
May 7, 2025

CVE-2025-47638 on NVD →

WP Discord Invite < 2.5.1 - Cross-Site Request Forgery to Settings Update

medium

The WP Discord Invite plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to 2.5.1. This is due to missing or incorrect nonce validation. This makes it possible for unauthenticated attackers to update settings via a forged request granted they can trick a site administrator into performing a...

CVSS:
5.4
Affected:
up to 2.5.1
Fixed in:
2.5.1
Disclosed:
Nov 7, 2023

CVE-2023-5006 on NVD →

WP Discord Invite <= 2.5.1 - Authenticated (Admin+) Stored Cross-Site Scripting

medium

The WP Discord Invite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 2.5.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject...

CVSS:
4.4
Affected:
up to 2.5.1
Fixed in:
2.5.2
Disclosed:
Oct 16, 2023

CVE-2023-5181 on NVD →

WP Discord Invite <= 2.4.1 - Reflected Cross-Site Scripting via webhook

medium

The WP Discord Invite plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘webhook’ parameter in versions up to, and including, 2.4.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that ex...

CVSS:
6.1
Affected:
up to 2.4.1
Fixed in:
2.5.1
Disclosed:
Sep 24, 2023

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database