plugin

Wp Experiments Free Vulnerabilities

6 known security issues reported for the Wp Experiments Free WordPress plugin. Most recent disclosed Jan 9, 2025.

1 critical 2 medium

Running Wp Experiments Free on your site? Check whether your installed version is affected.

Scan your site free

Title Experiments Free [wp-experiments-free] <= 9.0.4 (unfixed + closed)

unknown

[en] Missing Authorization vulnerability in Jason Funk Title Experiments Free allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Title Experiments Free: from n/a through 9.0.4.

Affected:
up to 9.0.4
Fix:
No patched version reported
Disclosed:
Jan 9, 2025

CVE-2025-22561 on NVD →

Title Experiments Free <= 9.0.4 - Cross-Site Request Forgery

medium

The Title Experiments Free plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 9.0.4. This is due to missing or incorrect nonce validation on a function. This makes it possible for unauthenticated attackers to perform an unauthorized action via a forged request granted the...

CVSS:
4.3
Affected:
up to 9.0.4
Fix:
No patched version reported
Disclosed:
Jan 7, 2025

CVE-2025-22562 on NVD →

Title Experiments Free <= 9.0.4 - Missing Authorization

medium

The Title Experiments Free plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 9.0.4. This makes it possible for authenticated attackers, with Subscriber-level access and above, to perform an unauthorized action.

CVSS:
4.3
Affected:
up to 9.0.4
Fix:
No patched version reported
Disclosed:
Jan 7, 2025

CVE-2025-22561 on NVD →

Title Experiments Free [wp-experiments-free] <= 9.0.4 (unfixed + closed)

unknown

[en] Cross-Site Request Forgery (CSRF) vulnerability in Jason Funk Title Experiments Free allows Cross Site Request Forgery.This issue affects Title Experiments Free: from n/a through 9.0.4.

Affected:
up to 9.0.4
Fix:
No patched version reported
Disclosed:
Jan 7, 2025

CVE-2025-22562 on NVD →

Title Experiments Free [wp-experiments-free] < 9.0.1 (closed)

unknown

[en] The Title Experiments Free WordPress plugin before 9.0.1 does not sanitise and escape the id parameter before using it in a SQL statement via the wpex_titles AJAX action (available to unauthenticated users), leading to an unauthenticated SQL injection

Affected:
up to 9.0.1
Fixed in:
9.0.1
Disclosed:
Mar 28, 2022

CVE-2022-0784 on NVD →

Title Experiments Free <= 9.0.0 - SQL Injection

critical

The Title Experiments Free Plugin for WordPress is vulnerable to blind SQL Injection via the ‘wpex_titles' AJAX action parameter in versions up to, and including, 9.0 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for una...

CVSS:
9.8
Affected:
up to 9.0.1
Fixed in:
9.0.1
Disclosed:
Mar 7, 2022

CVE-2022-0784 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database