plugin

Wp Dummy Content Generator Vulnerabilities

10 known security issues reported for the Wp Dummy Content Generator WordPress plugin. Most recent disclosed Jun 17, 2025.

1 critical 4 medium

Running Wp Dummy Content Generator on your site? Check whether your installed version is affected.

Scan your site free

WP Dummy Content Generator [wp-dummy-content-generator] < 4.0.0

unknown

[en] Missing Authorization vulnerability in Deepak anand WP Dummy Content Generator allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects WP Dummy Content Generator: from n/a through 3.4.6.

Affected:
up to 4.0.0
Fixed in:
4.0.0
Disclosed:
Jun 17, 2025

CVE-2025-49234 on NVD →

WP Dummy Content Generator <= 3.4.6 - Missing Authorization to Authenticated (Subscriber+) Arbitrary User Deletion

medium

The WP Dummy Content Generator plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 3.4.6. This makes it possible for authenticated attackers, with Subscriber-level access and above, to delete arbitrary user accounts.

CVSS:
4.3
Affected:
up to 3.4.6
Fixed in:
4.0.0
Disclosed:
Jun 16, 2025

CVE-2025-49234 on NVD →

WP Dummy Content Generator [wp-dummy-content-generator] < 3.0.0

unknown

[en] Missing Authorization vulnerability in Deepak anand WP Dummy Content Generator.This issue affects WP Dummy Content Generator: from n/a through 2.3.0.

Affected:
up to 3.0.0
Fixed in:
3.0.0
Disclosed:
Jun 13, 2024

CVE-2023-37394 on NVD →

WP Dummy Content Generator [wp-dummy-content-generator] < 3.3.0

unknown

[en] Improper Control of Generation of Code ('Code Injection') vulnerability in Deepak anand WP Dummy Content Generator.This issue affects WP Dummy Content Generator: from n/a through 3.2.1.

Affected:
up to 3.3.0
Fixed in:
3.3.0
Disclosed:
Apr 18, 2024

CVE-2024-32599 on NVD →

WP Dummy Content Generator <= 3.2.1 - Unauthenticated Code Injection

critical

The WP Dummy Content Generator plugin for WordPress is vulnerable to Remote Code Execution in all versions up to 3.3.0 (exclusive). This makes it possible for unauthenticated attackers to execute code on the server.

CVSS:
10
Affected:
up to 3.2.1
Fixed in:
3.3.0
Disclosed:
Apr 16, 2024

CVE-2024-32599 on NVD →

WP Dummy Content Generator [wp-dummy-content-generator] < 3.1.3

unknown

[en] Missing Authorization vulnerability in Deepak anand WP Dummy Content Generator.This issue affects WP Dummy Content Generator: from n/a through 3.1.2.

Affected:
up to 3.1.3
Fixed in:
3.1.3
Disclosed:
Mar 26, 2024

CVE-2024-24805 on NVD →

WP Dummy Content Generator <= 3.1.2 - Missing Authorization

medium

The WP Dummy Content Generator plugin for WordPress is vulnerable to unauthorized modification of data due to missing capability check son the wp_dummy_content_generatorDeletePosts() and wp_dummy_content_generatorAjaxGenPosts() functions in versions up to, and including, 3.1.2. This makes it possible for unauthenticate...

CVSS:
5.3
Affected:
up to 3.1.2
Fixed in:
3.1.3
Disclosed:
Feb 2, 2024

CVE-2024-24805 on NVD →

WP Dummy Content Generator [wp-dummy-content-generator] < 3.0.0

unknown

[en] Cross-Site Request Forgery (CSRF) vulnerability in Deepak Anand WP Dummy Content Generator plugin <= 2.3.0 versions.

Affected:
up to 3.0.0
Fixed in:
3.0.0
Disclosed:
Jul 10, 2023

CVE-2023-37392 on NVD →

WP Dummy Content Generator <= 2.3.0 - Missing Authorization

medium

The WP Dummy Content Generator plugin for WordPress is vulnerable to unauthorized use of functionality due to a missing capability check on one of its functions in versions up to, and including, 2.3.0. This makes it possible for unauthenticated attackers to make use of this functionality.

CVSS:
5.3
Affected:
up to 2.3.0
Fixed in:
3.0.0
Disclosed:
Jul 5, 2023

CVE-2023-37394 on NVD →

WP Dummy Content Generator <= 2.3.0 - Cross-Site Request Forgery

medium

The WP Dummy Content Generator plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.3.0. This is due to missing or incorrect nonce validation on one of its functions. This makes it possible for unauthenticated attackers to invoke that function via a forged request granted...

CVSS:
4.3
Affected:
up to 2.3.0
Fixed in:
3.0.0
Disclosed:
Jul 5, 2023

CVE-2023-37392 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database