plugin

Wpjam Basic Vulnerabilities

9 known security issues reported for the Wpjam Basic WordPress plugin. Most recent disclosed Aug 10, 2026.

3 high 3 medium

Running Wpjam Basic on your site? Check whether your installed version is affected.

Scan your site free

WPJAM Basic <= 7.0.1 - Authenticated (Subscriber+) SQL Injection

medium

The WPJAM Basic plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 7.0.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with subscriber-level access and above...

CVSS:
6.5
Affected:
up to 7.0.1
Fixed in:
7.0.2
Disclosed:
Aug 10, 2026

CVE-2026-61966 on NVD →

WPJAM Basic <= 7.0.2.1 - Authenticated (Subscriber+) Information Exposure

medium

The WPJAM Basic plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 7.0.2.1. This makes it possible for authenticated attackers, with subscriber-level access and above, to extract sensitive user or configuration data.

CVSS:
4.3
Affected:
up to 7.0.2.1
Fixed in:
7.0.3
Disclosed:
Aug 7, 2026

CVE-2026-66432 on NVD →

WPJAM Basic <= 7.0 - Authenticated (Contributor+) PHP Object Injection

high

The WPJAM Basic plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 7.0 via deserialization of untrusted input. This makes it possible for authenticated attackers, with contributor-level access and above, to inject a PHP Object. No known POP chain is present in the vulnerable so...

CVSS:
7.5
Affected:
up to 7.0
Fixed in:
7.0.1
Disclosed:
Jul 7, 2026

CVE-2026-57371 on NVD →

WPJAM Basic <= 7.0 - Unauthenticated Server-Side Request Forgery

high

The WPJAM Basic plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 7.0. This makes it possible for unauthenticated attackers to make web requests to arbitrary locations originating from the web application which can be used to query and modify information from intern...

CVSS:
7.2
Affected:
up to 7.0
Fixed in:
7.0.1
Disclosed:
Jul 7, 2026

CVE-2026-57372 on NVD →

WPJAM Basic [wpjam-basic] <= 6.9.2 (unfixed)

unknown

[en] Unrestricted Upload of File with Dangerous Type vulnerability in denishua WPJAM Basic wpjam-basic allows Using Malicious Files.This issue affects WPJAM Basic: from n/a through <= 6.9.2.

Affected:
up to 6.9.2
Fix:
No patched version reported
Disclosed:
Mar 25, 2026

CVE-2026-32523 on NVD →

WPJAM Basic <= 6.9.2 - Authenticated (Subscriber+) Arbitrary File Upload

high

The WPJAM Basic plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in all versions up to, and including, 6.9.2. This makes it possible for authenticated attackers, with Subscriber-level access and above, to upload arbitrary files on the affected site's server which may make...

CVSS:
8.8
Affected:
up to 6.9.2
Fixed in:
6.9.2.1
Disclosed:
Mar 20, 2026

CVE-2026-32523 on NVD →

WPJAM Basic [wpjam-basic] < 6.6.1.3

unknown

<p>WordPress WPJAM Basic Plugin <= 6.5.4.1 is vulnerable to Backdoor</p><p>Software: WPJAM Basic</p><p>Link: https://wordpress.org/plugins/wpjam-basic/#developers</p><p>Affected Version <= 6.5.4.1</p>

Affected:
up to 6.6.1.3
Fixed in:
6.6.1.3
Disclosed:
Jul 3, 2024

WPJAM Basic [wpjam-basic] < 6.2.1.1

unknown

[en] Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Denis WPJAM Basic plugin <= 6.2.1 versions.

Affected:
up to 6.2.1.1
Fixed in:
6.2.1.1
Disclosed:
May 16, 2023

CVE-2023-23709 on NVD →

WPJAM Basic <= 6.2.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode

medium

The WPJAM Basic plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in versions up to, and including, 6.2.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and ab...

CVSS:
6.4
Affected:
up to 6.2.1
Fixed in:
6.2.1.1
Disclosed:
Apr 20, 2023

CVE-2023-23709 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database