WPtouch – Make your WordPress Website Mobile-Friendly [wptouch] < 4.3.61
unknown
[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPtouch WPtouch allows Stored XSS. This issue affects WPtouch: from n/a through 4.3.60.
- Affected:
- up to 4.3.61
- Fixed in:
- 4.3.61
- Disclosed:
- Jun 6, 2025
CVE-2025-49318 on NVD →
WPtouch <= 4.3.60 - Authenticated (Administrator+) Stored Cross-Site Scripting
medium
The WPtouch plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 4.3.60 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level access and above, to inject arbitrary web scripts in pages that...
- CVSS:
- 4.4
- Affected:
- up to 4.3.60
- Fixed in:
- 4.3.61
- Disclosed:
- Jun 5, 2025
CVE-2025-49318 on NVD →
WPtouch – Make your WordPress Website Mobile-Friendly [wptouch] < 4.3.45
unknown
[en] The WPtouch WordPress plugin before 4.3.45 does not properly validate images to be uploaded, allowing high privilege users such as admin to upload arbitrary files on the server even when they should not be allowed to (for example in multisite setup)
- Affected:
- up to 4.3.45
- Fixed in:
- 4.3.45
- Disclosed:
- Jan 9, 2023
CVE-2022-3416 on NVD →
WPtouch – Make your WordPress Website Mobile-Friendly [wptouch] < 4.3.45
unknown
[en] The WPtouch WordPress plugin before 4.3.45 unserialises the content of an imported settings file, which could lead to PHP object injections issues when an user import (intentionally or not) a malicious settings file and a suitable gadget chain is present on the blog.
- Affected:
- up to 4.3.45
- Fixed in:
- 4.3.45
- Disclosed:
- Jan 9, 2023
CVE-2022-3417 on NVD →
WPtouch <= 4.3.44 - Authenticated (Administrator+) PHP Object Injection
high
The WPtouch plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 4.3.44 via deserialization of untrusted input when importing settings. This allows administrator-level attackers to inject a PHP Object. No POP chain is present in the vulnerable plugin. If a POP chain is present vi...
- CVSS:
- 7.2
- Affected:
- up to 4.3.44
- Fixed in:
- 4.3.45
- Disclosed:
- Dec 19, 2022
CVE-2022-3417 on NVD →
WPtouch <= 4.3.44 - Authenticated (Administrator+) Arbitrary File Upload
high
The WPtouch plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation when uploading images in versions up to, and including, 4.3.44. This makes it possible for authenticated attackers, with administrator-level permissions and above, to upload arbitrary files on the affected sites...
- CVSS:
- 7.2
- Affected:
- up to 4.3.44
- Fixed in:
- 4.3.45
- Disclosed:
- Dec 19, 2022
CVE-2022-3416 on NVD →
WPtouch – Make your WordPress Website Mobile-Friendly [wptouch] < 4.3.44
unknown
Reflected Cross-Site Scripting (XSS) vulnerability discovered by WPScan in WordPress WPtouch plugin (versions <= 4.3.42).
Update the WordPress WPtouch plugin to the latest available version (at least 4.3.44).
- Affected:
- up to 4.3.44
- Fixed in:
- 4.3.44
- Disclosed:
- Aug 29, 2022
WPtouch <= 4.3.42 - Reflected Cross-Site Scripting
medium
The WPtouch plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in versions up to, and including, 4.3.42. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can succes...
- CVSS:
- 6.1
- Affected:
- up to 4.3.42
- Fixed in:
- 4.3.44
- Disclosed:
- Aug 25, 2022
WPtouch – Make your WordPress Website Mobile-Friendly [wptouch] < 4.3.44
unknown
The WPtouch plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in versions up to, and including, 4.3.42. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can succes...
- Affected:
- up to 4.3.44
- Fixed in:
- 4.3.44
- Disclosed:
- Aug 25, 2022
WPtouch <= 3.7.5.3 - Cross-Site Scripting
high
The WPtouch plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including, 3.7.5.3 due to insufficient input sanitization and output escaping. This makes it possible for attackers to inject arbitrary web scripts that execute in a victim's browser.
- CVSS:
- 7.2
- Affected:
- up to 3.7.6
- Fixed in:
- 3.7.6
- Disclosed:
- Apr 20, 2015
WPtouch – Make your WordPress Website Mobile-Friendly [wptouch] < 3.7.6
unknown
The WPtouch plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including, 3.7.5.3 due to insufficient input sanitization and output escaping. This makes it possible for attackers to inject arbitrary web scripts that execute in a victim's browser.
- Affected:
- up to 3.7.6
- Fixed in:
- 3.7.6
- Disclosed:
- Apr 20, 2015
WPTouch < 3.7 - Open Redirect
medium
The WPTouch plugin for WordPress is vulnerable to an open redirect in versions before 3.7. This allows attackers to use a trusted site to trick victims into being redirected to an untrusted site.
- CVSS:
- 4.3
- Affected:
- up to 3.7
- Fixed in:
- 3.7
- Disclosed:
- Jan 29, 2015
WPtouch – Make your WordPress Website Mobile-Friendly [wptouch] < 3.7
unknown
The WPTouch plugin for WordPress is vulnerable to an open redirect in versions before 3.7. This allows attackers to use a trusted site to trick victims into being redirected to an untrusted site.
- Affected:
- up to 3.7
- Fixed in:
- 3.7
- Disclosed:
- Jan 29, 2015
WPtouch – Make your WordPress Website Mobile-Friendly [wptouch] < 3.7
unknown
This plugin is prone to an unvalidated open redirection vulnerability.
Update the plugin.
- Affected:
- up to 3.7
- Fixed in:
- 3.7
- Disclosed:
- Jan 29, 2015
WPtouch <= 3.4.2 - Arbitrary File Upload
critical
The WPtouch plugin for WordPress is vulnerable to arbitrary file upload in versions up to, and including, 3.4.2. This is due to the 'admin_initialize()' method being called by the 'admin_init' hook and a lack of capability checks on the function. This makes it possible for authenticated attackers to upload a backdoor,...
- CVSS:
- 9.9
- Affected:
- up to 3.4.2
- Fixed in:
- 3.4.3
- Disclosed:
- Aug 1, 2014
WPtouch < 1.9.30 - Open Redirect
medium
The WPtouch plugin for WordPress is vulnerable to Open Redirect in versions before 1.9.30. This is due to insufficient input sanitization via the 'wptouch_redirect' parameter. This makes it possible for attackers to construct a URL which causes a redirection to an arbitrary external domain.
- CVSS:
- 6.1
- Affected:
- up to 1.9.30
- Fixed in:
- 1.9.30
- Disclosed:
- Aug 1, 2014
WPtouch – Make your WordPress Website Mobile-Friendly [wptouch] < 3.4.3
unknown
Because of this vulnerability, a logged-in attacker can potentially take over the website by uploading a backdoor and then do anything he wants.
Update the plugin.
- Affected:
- up to 3.4.3
- Fixed in:
- 3.4.3
- Disclosed:
- Aug 1, 2014
WPtouch – Make your WordPress Website Mobile-Friendly [wptouch] < 3.4.3
unknown
The WPtouch plugin for WordPress is vulnerable to arbitrary file upload in versions up to, and including, 3.4.2. This is due to the 'admin_initialize()' method being called by the 'admin_init' hook and a lack of capability checks on the function. This makes it possible for authenticated attackers to upload a backdoor,...
- Affected:
- up to 3.4.3
- Fixed in:
- 3.4.3
- Disclosed:
- Aug 1, 2014
WPtouch – Make your WordPress Website Mobile-Friendly [wptouch] < 1.9.30
unknown
The WPtouch plugin for WordPress is vulnerable to Open Redirect in versions before 1.9.30. This is due to insufficient input sanitization via the 'wptouch_redirect' parameter. This makes it possible for attackers to construct a URL which causes a redirection to an arbitrary external domain.
- Affected:
- up to 1.9.30
- Fixed in:
- 1.9.30
- Disclosed:
- Aug 1, 2014
WPtouch – Make your WordPress Website Mobile-Friendly [wptouch] < 1.9.8.1
unknown
This plugin is prone to an SQL injection vulnerability in include/submit.php parameter.
Update the plugin.
- Affected:
- up to 1.9.8.1
- Fixed in:
- 1.9.8.1
- Disclosed:
- Aug 1, 2014
WPtouch – Make your WordPress Website Mobile-Friendly [wptouch] < 1.9.8.1
unknown
This plugin is prone to a remote code execution in ajax/file_upload.php.
Update the plugin.
- Affected:
- up to 1.9.8.1
- Fixed in:
- 1.9.8.1
- Disclosed:
- Aug 1, 2014
WPtouch – Make your WordPress Website Mobile-Friendly [wptouch] < 1.9.8.1
unknown
[en] SQL injection vulnerability in wptouch/ajax.php in the WPTouch plugin for WordPress allows remote attackers to execute arbitrary SQL commands via the id parameter.
- Affected:
- up to 1.9.8.1
- Fixed in:
- 1.9.8.1
- Disclosed:
- Dec 14, 2011
CVE-2011-4803 on NVD →
WPtouch <= 1.9.8 - SQL Injection
high
SQL injection vulnerability in wptouch/ajax.php in the WPTouch plugin for WordPress allows remote attackers to execute arbitrary SQL commands via the id parameter.
- CVSS:
- 7.3
- Affected:
- up to 1.9.8.1
- Fixed in:
- 1.9.8.1
- Disclosed:
- Oct 27, 2011
CVE-2011-4803 on NVD →
WPtouch – Make your WordPress Website Mobile-Friendly [wptouch] < 1.9.3
unknown
This WordPress WPtouch plugin is prone to an URL redirection vulnerability.
- Affected:
- up to 1.9.3
- Fixed in:
- 1.9.3
- Disclosed:
- Jun 21, 2011
WPtouch – Make your WordPress Website Mobile-Friendly [wptouch] < 1.9.20
unknown
[en] Cross-site scripting (XSS) vulnerability in lib/includes/auth.inc.php in the WPtouch plugin 1.9.19.4 and 1.9.20 for WordPress allows remote attackers to inject arbitrary web script or HTML via the wptouch_settings parameter to include/adsense-new.php. NOTE: some of these details are obtained from third party info...
- Affected:
- up to 1.9.20
- Fixed in:
- 1.9.20
- Disclosed:
- Apr 7, 2011
CVE-2010-4779 on NVD →
WPtouch < 1.9.20 - Cross-Site Scripting
medium
Cross-site scripting (XSS) vulnerability in lib/includes/auth.inc.php in the WPtouch plugin 1.9.19.4 and 1.9.20 for WordPress allows remote attackers to inject arbitrary web script or HTML via the wptouch_settings parameter to include/adsense-new.php.
- CVSS:
- 6.1
- Affected:
- up to 1.9.20
- Fixed in:
- 1.9.20
- Disclosed:
- Dec 1, 2010
CVE-2010-4779 on NVD →
WPtouch – Make your WordPress Website Mobile-Friendly [wptouch] < 4.3.44
unknown
The plugin does not escape an URL before outputting it back in an attribute, leading to Reflected Cross-Site Scripting
- Affected:
- up to 4.3.44
- Fixed in:
- 4.3.44
WPtouch – Make your WordPress Website Mobile-Friendly [wptouch] < 3.7.6
unknown
The WPtouch WordPress plugin was affected by a Cross-Site Scripting (XSS) security vulnerability.
- Affected:
- up to 3.7.6
- Fixed in:
- 3.7.6
WPtouch – Make your WordPress Website Mobile-Friendly [wptouch] < 3.7
unknown
The WPtouch WordPress plugin was affected by an Unvalidated Open Redirect security vulnerability.
- Affected:
- up to 3.7
- Fixed in:
- 3.7
WPtouch – Make your WordPress Website Mobile-Friendly [wptouch] < 1.9.30
unknown
The WPtouch WordPress plugin was affected by a 'wptouch_redirect' Parameter URI Redirection security vulnerability.
- Affected:
- up to 1.9.30
- Fixed in:
- 1.9.30
WPtouch – Make your WordPress Website Mobile-Friendly [wptouch] < 1.9.8.1
unknown
The WPtouch WordPress plugin was affected by an ajax/file_upload.php Crafted Content-Type File Upload Remote Code Execution security vulnerability.
- Affected:
- up to 1.9.8.1
- Fixed in:
- 1.9.8.1
WPtouch – Make your WordPress Website Mobile-Friendly [wptouch] < 1.9.8.1
unknown
The WPtouch WordPress plugin was affected by an include/submit.php Multiple Parameter SQL Injection security vulnerability.
- Affected:
- up to 1.9.8.1
- Fixed in:
- 1.9.8.1
WPtouch – Make your WordPress Website Mobile-Friendly [wptouch] < 3.4.3
unknown
The WPtouch WordPress plugin was affected by an Insecure Nonce Generation security vulnerability.
- Affected:
- up to 3.4.3
- Fixed in:
- 3.4.3
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database