WP Plugin Info Card <= 6.2.0 - Cross-Site Request Forgery to Arbitrary Custom Plugin Entry Creation
medium
The WP Plugin Info Card plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 6.2.0. This is due to missing nonce validation in the ajax_save_custom_plugin() function, which is disabled by prefixing the check with 'false &&'. This makes it possible for unauthenticated at...
- CVSS:
- 4.3
- Affected:
- up to 6.2.0
- Fixed in:
- 6.3.0
- Disclosed:
- Feb 17, 2026
CVE-2026-2023 on NVD →
WP Plugin Info Card <= 5.3.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via containerid Parameter
medium
The WP Plugin Info Card plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘containerid’ parameter in all versions up to, and including, 5.3.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, t...
- CVSS:
- 6.4
- Affected:
- up to 5.3.1
- Fixed in:
- 5.4.0
- Disclosed:
- Jun 2, 2025
CVE-2025-5116 on NVD →
WP Plugin Info Card <= 5.3.0 - Authenticated (Contributor+) Stored Cross-Site Scripting
medium
The WP Plugin Info Card plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 5.3.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pa...
- CVSS:
- 6.4
- Affected:
- up to 5.3.0
- Fixed in:
- 5.3.1
- Disclosed:
- Apr 1, 2025
CVE-2025-31835 on NVD →
WP Plugin Info Card [wp-plugin-info-card] < 5.3.1
unknown
[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Brice Capobianco WP Plugin Info Card allows DOM-Based XSS. This issue affects WP Plugin Info Card: from n/a through 5.2.5.
- Affected:
- up to 5.3.1
- Fixed in:
- 5.3.1
- Disclosed:
- Apr 1, 2025
CVE-2025-31835 on NVD →
WP Plugin Info Card < 2.3.7 - Cross-Site Scripting
medium
The WP Plugin Info Card plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘slug’ parameter in versions up to, and including, 2.3.6 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that exe...
- CVSS:
- 6.1
- Affected:
- up to 2.3.7
- Fixed in:
- 2.3.7
- Disclosed:
- Mar 4, 2015
WP Plugin Info Card [wp-plugin-info-card] < 2.3.7
unknown
The WP Plugin Info Card plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘slug’ parameter in versions up to, and including, 2.3.6 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that exe...
- Affected:
- up to 2.3.7
- Fixed in:
- 2.3.7
- Disclosed:
- Mar 4, 2015
WP Plugin Info Card [wp-plugin-info-card] < 2.3.7
unknown
Authenticated XSS via wppic-list POST parameter in the wppic_widget_render() AJAX method (which is also lacking CSRF and authorisation checks, even in the fixed version)
- Affected:
- up to 2.3.7
- Fixed in:
- 2.3.7
WP Plugin Info Card [wp-plugin-info-card] < 5.4.0
unknown
- Affected:
- up to 5.4.0
- Fixed in:
- 5.4.0
CVE-2025-5116 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database