plugin

Wp Plugin Info Card Vulnerabilities

8 known security issues reported for the Wp Plugin Info Card WordPress plugin. Most recent disclosed Feb 17, 2026.

4 medium

Running Wp Plugin Info Card on your site? Check whether your installed version is affected.

Scan your site free

WP Plugin Info Card <= 6.2.0 - Cross-Site Request Forgery to Arbitrary Custom Plugin Entry Creation

medium

The WP Plugin Info Card plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 6.2.0. This is due to missing nonce validation in the ajax_save_custom_plugin() function, which is disabled by prefixing the check with 'false &&'. This makes it possible for unauthenticated at...

CVSS:
4.3
Affected:
up to 6.2.0
Fixed in:
6.3.0
Disclosed:
Feb 17, 2026

CVE-2026-2023 on NVD →

WP Plugin Info Card <= 5.3.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via containerid Parameter

medium

The WP Plugin Info Card plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘containerid’ parameter in all versions up to, and including, 5.3.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, t...

CVSS:
6.4
Affected:
up to 5.3.1
Fixed in:
5.4.0
Disclosed:
Jun 2, 2025

CVE-2025-5116 on NVD →

WP Plugin Info Card <= 5.3.0 - Authenticated (Contributor+) Stored Cross-Site Scripting

medium

The WP Plugin Info Card plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 5.3.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pa...

CVSS:
6.4
Affected:
up to 5.3.0
Fixed in:
5.3.1
Disclosed:
Apr 1, 2025

CVE-2025-31835 on NVD →

WP Plugin Info Card [wp-plugin-info-card] < 5.3.1

unknown

[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Brice Capobianco WP Plugin Info Card allows DOM-Based XSS. This issue affects WP Plugin Info Card: from n/a through 5.2.5.

Affected:
up to 5.3.1
Fixed in:
5.3.1
Disclosed:
Apr 1, 2025

CVE-2025-31835 on NVD →

WP Plugin Info Card < 2.3.7 - Cross-Site Scripting

medium

The WP Plugin Info Card plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘slug’ parameter in versions up to, and including, 2.3.6 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that exe...

CVSS:
6.1
Affected:
up to 2.3.7
Fixed in:
2.3.7
Disclosed:
Mar 4, 2015

WP Plugin Info Card [wp-plugin-info-card] < 2.3.7

unknown

The WP Plugin Info Card plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘slug’ parameter in versions up to, and including, 2.3.6 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that exe...

Affected:
up to 2.3.7
Fixed in:
2.3.7
Disclosed:
Mar 4, 2015

WP Plugin Info Card [wp-plugin-info-card] < 2.3.7

unknown

Authenticated XSS via wppic-list POST parameter in the wppic_widget_render() AJAX method (which is also lacking CSRF and authorisation checks, even in the fixed version)

Affected:
up to 2.3.7
Fixed in:
2.3.7

WP Plugin Info Card [wp-plugin-info-card] < 5.4.0

unknown
Affected:
up to 5.4.0
Fixed in:
5.4.0

CVE-2025-5116 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database