WP Editor <= 1.2.9.2 - Cross-Site Request Forgery to Remote Code Execution via Plugin and Theme File Editor
high
The WP Editor plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.2.9.2. This is due to missing nonce verification in the 'add_plugins_page' and 'add_themes_page' functions. This makes it possible for unauthenticated attackers to overwrite arbitrary plugin and theme...
- CVSS:
- 8.8
- Affected:
- up to 1.2.9.2
- Fixed in:
- 1.2.9.3
- Disclosed:
- Apr 30, 2026
CVE-2026-3772 on NVD →
WP Editor <= 1.2.9.1 - Authenticated (Administrator+) Directory Traversal to Arbitrary File Read
medium
The WP Editor plugin for WordPress is vulnerable to arbitrary file read in all versions up to, and including, 1.2.9.1. This makes it possible for authenticated attackers, with Administrator-level access and above, to read arbitrary files on the affected site's server which may reveal sensitive information.
- CVSS:
- 4.9
- Affected:
- up to 1.2.9.1
- Fixed in:
- 1.2.9.2
- Disclosed:
- Apr 16, 2025
CVE-2025-3295 on NVD →
WP Editor <= 1.2.9.1 - Authenticated (Administrator+) Directory Traversal to Arbitrary File Update
high
The WP Editor plugin for WordPress is vulnerable to arbitrary file update due to missing file path validation in all versions up to, and including, 1.2.9.1. This makes it possible for authenticated attackers, with Administrator-level access and above, to overwrite arbitrary files on the affected site's server which may...
- CVSS:
- 7.2
- Affected:
- up to 1.2.9.1
- Fixed in:
- 1.2.9.2
- Disclosed:
- Apr 16, 2025
CVE-2025-3294 on NVD →
WP Editor <= 1.2.9 - Authenticated (Admin+) PHAR Deserialization
high
The WP Editor plugin for WordPress is vulnerable to deserialization of untrusted input via the 'current_theme_root' parameter in versions up to, and including 1.2.9. This makes it possible for authenticated attackers with administrative privileges to call files using a PHAR wrapper that will deserialize and call arbitr...
- CVSS:
- 7.2
- Affected:
- up to 1.2.9
- Fixed in:
- 1.2.9.1
- Disclosed:
- Sep 12, 2024
CVE-2022-2446 on NVD →
WP Editor <= 1.2.8 - Reflected Cross-Site Scripting
medium
The WP Editor plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and including, 1.2.8 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully t...
- CVSS:
- 6.1
- Affected:
- up to 1.2.8
- Fixed in:
- 1.2.9
- Disclosed:
- Mar 26, 2024
CVE-2024-24700 on NVD →
WP Editor <= 1.2.7 - Sensitive Information Exposure via log file
medium
The WP Editor plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.2.7 via the plugin's log file. This makes it possible for unauthenticated attackers to extract sensitive data including configuration information.
- CVSS:
- 5.3
- Affected:
- up to 1.2.7
- Fixed in:
- 1.2.8
- Disclosed:
- Feb 12, 2024
CVE-2024-25591 on NVD →
WP Editor <= 1.2.6.3 - Authenticated (Admin+) SQL injection
high
The WP Editor plugin for WordPress is vulnerable to blind SQL Injection via the setting fields in versions up to, and including, 1.2.6.3 due to insufficient escaping on the user-supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated admin+ attackers to...
- CVSS:
- 7.2
- Affected:
- up to 1.2.6.3
- Fixed in:
- 1.2.7
- Disclosed:
- Feb 1, 2021
CVE-2021-24151 on NVD →
WP Editor < 1.2.6 - Incorrect Permission Assignment or Protection
critical
The wp-editor plugin before 1.2.6 for WordPress has incorrect permissions.
- CVSS:
- 9.8
- Affected:
- up to 1.2.6
- Fixed in:
- 1.2.6
- Disclosed:
- Jan 15, 2021
CVE-2016-10886 on NVD →
WP Editor <= 1.2.6.2 - Cross-Site Scripting
medium
The wp-editor plugin before 1.2.6.3 for WordPress has multiple XSS issues.
- CVSS:
- 6.1
- Affected:
- up to 1.2.6.3
- Fixed in:
- 1.2.6.3
- Disclosed:
- Oct 5, 2016
CVE-2016-10877 on NVD →
WP Editor < 1.2.6 - Cross-Site Request Forgery
high
The WP Editor plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to 1.2.6. This is due to missing or incorrect nonce validation on the save_settings() function, in addition to a few other functions. This makes it possible for unauthenticated attackers to modify the plugin's settings and upl...
- CVSS:
- 8.8
- Affected:
- up to 1.2.6
- Fixed in:
- 1.2.6
- Disclosed:
- May 13, 2016
CVE-2016-10885 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database