WPJAM Basic <= 7.0.1 - Authenticated (Subscriber+) SQL Injection
medium
The WPJAM Basic plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 7.0.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with subscriber-level access and above...
- CVSS:
- 6.5
- Affected:
- up to 7.0.1
- Fixed in:
- 7.0.2
- Disclosed:
- Aug 10, 2026
CVE-2026-61966 on NVD →
WPJAM Basic <= 7.0.2.1 - Authenticated (Subscriber+) Information Exposure
medium
The WPJAM Basic plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 7.0.2.1. This makes it possible for authenticated attackers, with subscriber-level access and above, to extract sensitive user or configuration data.
- CVSS:
- 4.3
- Affected:
- up to 7.0.2.1
- Fixed in:
- 7.0.3
- Disclosed:
- Aug 7, 2026
CVE-2026-66432 on NVD →
WPJAM Basic <= 7.0 - Authenticated (Contributor+) PHP Object Injection
high
The WPJAM Basic plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 7.0 via deserialization of untrusted input. This makes it possible for authenticated attackers, with contributor-level access and above, to inject a PHP Object. No known POP chain is present in the vulnerable so...
- CVSS:
- 7.5
- Affected:
- up to 7.0
- Fixed in:
- 7.0.1
- Disclosed:
- Jul 7, 2026
CVE-2026-57371 on NVD →
WPJAM Basic <= 7.0 - Unauthenticated Server-Side Request Forgery
high
The WPJAM Basic plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 7.0. This makes it possible for unauthenticated attackers to make web requests to arbitrary locations originating from the web application which can be used to query and modify information from intern...
- CVSS:
- 7.2
- Affected:
- up to 7.0
- Fixed in:
- 7.0.1
- Disclosed:
- Jul 7, 2026
CVE-2026-57372 on NVD →
WPJAM Basic [wpjam-basic] <= 6.9.2 (unfixed)
unknown
[en] Unrestricted Upload of File with Dangerous Type vulnerability in denishua WPJAM Basic wpjam-basic allows Using Malicious Files.This issue affects WPJAM Basic: from n/a through <= 6.9.2.
- Affected:
- up to 6.9.2
- Fix:
- No patched version reported
- Disclosed:
- Mar 25, 2026
CVE-2026-32523 on NVD →
WPJAM Basic <= 6.9.2 - Authenticated (Subscriber+) Arbitrary File Upload
high
The WPJAM Basic plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in all versions up to, and including, 6.9.2. This makes it possible for authenticated attackers, with Subscriber-level access and above, to upload arbitrary files on the affected site's server which may make...
- CVSS:
- 8.8
- Affected:
- up to 6.9.2
- Fixed in:
- 6.9.2.1
- Disclosed:
- Mar 20, 2026
CVE-2026-32523 on NVD →
WPJAM Basic [wpjam-basic] < 6.6.1.3
unknown
<p>WordPress WPJAM Basic Plugin <= 6.5.4.1 is vulnerable to Backdoor</p><p>Software: WPJAM Basic</p><p>Link: https://wordpress.org/plugins/wpjam-basic/#developers</p><p>Affected Version <= 6.5.4.1</p>
- Affected:
- up to 6.6.1.3
- Fixed in:
- 6.6.1.3
- Disclosed:
- Jul 3, 2024
WPJAM Basic [wpjam-basic] < 6.2.1.1
unknown
[en] Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Denis WPJAM Basic plugin <= 6.2.1 versions.
- Affected:
- up to 6.2.1.1
- Fixed in:
- 6.2.1.1
- Disclosed:
- May 16, 2023
CVE-2023-23709 on NVD →
WPJAM Basic <= 6.2.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode
medium
The WPJAM Basic plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in versions up to, and including, 6.2.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and ab...
- CVSS:
- 6.4
- Affected:
- up to 6.2.1
- Fixed in:
- 6.2.1.1
- Disclosed:
- Apr 20, 2023
CVE-2023-23709 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database