plugin

Wptouch Vulnerabilities

33 known security issues reported for the Wptouch WordPress plugin. Most recent disclosed Jun 6, 2025.

1 critical 4 high 5 medium

Running Wptouch on your site? Check whether your installed version is affected.

Scan your site free

WPtouch &#8211; Make your WordPress Website Mobile-Friendly [wptouch] < 4.3.61

unknown

[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPtouch WPtouch allows Stored XSS. This issue affects WPtouch: from n/a through 4.3.60.

Affected:
up to 4.3.61
Fixed in:
4.3.61
Disclosed:
Jun 6, 2025

CVE-2025-49318 on NVD →

WPtouch <= 4.3.60 - Authenticated (Administrator+) Stored Cross-Site Scripting

medium

The WPtouch plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 4.3.60 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level access and above, to inject arbitrary web scripts in pages that...

CVSS:
4.4
Affected:
up to 4.3.60
Fixed in:
4.3.61
Disclosed:
Jun 5, 2025

CVE-2025-49318 on NVD →

WPtouch &#8211; Make your WordPress Website Mobile-Friendly [wptouch] < 4.3.45

unknown

[en] The WPtouch WordPress plugin before 4.3.45 does not properly validate images to be uploaded, allowing high privilege users such as admin to upload arbitrary files on the server even when they should not be allowed to (for example in multisite setup)

Affected:
up to 4.3.45
Fixed in:
4.3.45
Disclosed:
Jan 9, 2023

CVE-2022-3416 on NVD →

WPtouch &#8211; Make your WordPress Website Mobile-Friendly [wptouch] < 4.3.45

unknown

[en] The WPtouch WordPress plugin before 4.3.45 unserialises the content of an imported settings file, which could lead to PHP object injections issues when an user import (intentionally or not) a malicious settings file and a suitable gadget chain is present on the blog.

Affected:
up to 4.3.45
Fixed in:
4.3.45
Disclosed:
Jan 9, 2023

CVE-2022-3417 on NVD →

WPtouch <= 4.3.44 - Authenticated (Administrator+) PHP Object Injection

high

The WPtouch plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 4.3.44 via deserialization of untrusted input when importing settings. This allows administrator-level attackers to inject a PHP Object. No POP chain is present in the vulnerable plugin. If a POP chain is present vi...

CVSS:
7.2
Affected:
up to 4.3.44
Fixed in:
4.3.45
Disclosed:
Dec 19, 2022

CVE-2022-3417 on NVD →

WPtouch <= 4.3.44 - Authenticated (Administrator+) Arbitrary File Upload

high

The WPtouch plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation when uploading images in versions up to, and including, 4.3.44. This makes it possible for authenticated attackers, with administrator-level permissions and above, to upload arbitrary files on the affected sites...

CVSS:
7.2
Affected:
up to 4.3.44
Fixed in:
4.3.45
Disclosed:
Dec 19, 2022

CVE-2022-3416 on NVD →

WPtouch &#8211; Make your WordPress Website Mobile-Friendly [wptouch] < 4.3.44

unknown

Reflected Cross-Site Scripting (XSS) vulnerability discovered by WPScan in WordPress WPtouch plugin (versions <= 4.3.42). Update the WordPress WPtouch plugin to the latest available version (at least 4.3.44).

Affected:
up to 4.3.44
Fixed in:
4.3.44
Disclosed:
Aug 29, 2022

WPtouch <= 4.3.42 - Reflected Cross-Site Scripting

medium

The WPtouch plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in versions up to, and including, 4.3.42. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can succes...

CVSS:
6.1
Affected:
up to 4.3.42
Fixed in:
4.3.44
Disclosed:
Aug 25, 2022

WPtouch &#8211; Make your WordPress Website Mobile-Friendly [wptouch] < 4.3.44

unknown

The WPtouch plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in versions up to, and including, 4.3.42. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can succes...

Affected:
up to 4.3.44
Fixed in:
4.3.44
Disclosed:
Aug 25, 2022

WPtouch <= 3.7.5.3 - Cross-Site Scripting

high

The WPtouch plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including, 3.7.5.3 due to insufficient input sanitization and output escaping. This makes it possible for attackers to inject arbitrary web scripts that execute in a victim's browser.

CVSS:
7.2
Affected:
up to 3.7.6
Fixed in:
3.7.6
Disclosed:
Apr 20, 2015

WPtouch &#8211; Make your WordPress Website Mobile-Friendly [wptouch] < 3.7.6

unknown

The WPtouch plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including, 3.7.5.3 due to insufficient input sanitization and output escaping. This makes it possible for attackers to inject arbitrary web scripts that execute in a victim's browser.

Affected:
up to 3.7.6
Fixed in:
3.7.6
Disclosed:
Apr 20, 2015

WPTouch < 3.7 - Open Redirect

medium

The WPTouch plugin for WordPress is vulnerable to an open redirect in versions before 3.7. This allows attackers to use a trusted site to trick victims into being redirected to an untrusted site.

CVSS:
4.3
Affected:
up to 3.7
Fixed in:
3.7
Disclosed:
Jan 29, 2015

WPtouch &#8211; Make your WordPress Website Mobile-Friendly [wptouch] < 3.7

unknown

The WPTouch plugin for WordPress is vulnerable to an open redirect in versions before 3.7. This allows attackers to use a trusted site to trick victims into being redirected to an untrusted site.

Affected:
up to 3.7
Fixed in:
3.7
Disclosed:
Jan 29, 2015

WPtouch &#8211; Make your WordPress Website Mobile-Friendly [wptouch] < 3.7

unknown

This plugin is prone to an unvalidated open redirection vulnerability. Update the plugin.

Affected:
up to 3.7
Fixed in:
3.7
Disclosed:
Jan 29, 2015

WPtouch <= 3.4.2 - Arbitrary File Upload

critical

The WPtouch plugin for WordPress is vulnerable to arbitrary file upload in versions up to, and including, 3.4.2. This is due to the 'admin_initialize()' method being called by the 'admin_init' hook and a lack of capability checks on the function. This makes it possible for authenticated attackers to upload a backdoor,...

CVSS:
9.9
Affected:
up to 3.4.2
Fixed in:
3.4.3
Disclosed:
Aug 1, 2014

WPtouch < 1.9.30 - Open Redirect

medium

The WPtouch plugin for WordPress is vulnerable to Open Redirect in versions before 1.9.30. This is due to insufficient input sanitization via the 'wptouch_redirect' parameter. This makes it possible for attackers to construct a URL which causes a redirection to an arbitrary external domain.

CVSS:
6.1
Affected:
up to 1.9.30
Fixed in:
1.9.30
Disclosed:
Aug 1, 2014

WPtouch &#8211; Make your WordPress Website Mobile-Friendly [wptouch] < 3.4.3

unknown

Because of this vulnerability, a logged­-in attacker can potentially take over the website by uploading a backdoor and then do anything he wants. Update the plugin.

Affected:
up to 3.4.3
Fixed in:
3.4.3
Disclosed:
Aug 1, 2014

WPtouch &#8211; Make your WordPress Website Mobile-Friendly [wptouch] < 3.4.3

unknown

The WPtouch plugin for WordPress is vulnerable to arbitrary file upload in versions up to, and including, 3.4.2. This is due to the 'admin_initialize()' method being called by the 'admin_init' hook and a lack of capability checks on the function. This makes it possible for authenticated attackers to upload a backdoor,...

Affected:
up to 3.4.3
Fixed in:
3.4.3
Disclosed:
Aug 1, 2014

WPtouch &#8211; Make your WordPress Website Mobile-Friendly [wptouch] < 1.9.30

unknown

The WPtouch plugin for WordPress is vulnerable to Open Redirect in versions before 1.9.30. This is due to insufficient input sanitization via the 'wptouch_redirect' parameter. This makes it possible for attackers to construct a URL which causes a redirection to an arbitrary external domain.

Affected:
up to 1.9.30
Fixed in:
1.9.30
Disclosed:
Aug 1, 2014

WPtouch &#8211; Make your WordPress Website Mobile-Friendly [wptouch] < 1.9.8.1

unknown

This plugin is prone to an SQL injection vulnerability in include/submit.php parameter. Update the plugin.

Affected:
up to 1.9.8.1
Fixed in:
1.9.8.1
Disclosed:
Aug 1, 2014

WPtouch &#8211; Make your WordPress Website Mobile-Friendly [wptouch] < 1.9.8.1

unknown

This plugin is prone to a remote code execution in ajax/file_upload.php. Update the plugin.

Affected:
up to 1.9.8.1
Fixed in:
1.9.8.1
Disclosed:
Aug 1, 2014

WPtouch &#8211; Make your WordPress Website Mobile-Friendly [wptouch] < 1.9.8.1

unknown

[en] SQL injection vulnerability in wptouch/ajax.php in the WPTouch plugin for WordPress allows remote attackers to execute arbitrary SQL commands via the id parameter.

Affected:
up to 1.9.8.1
Fixed in:
1.9.8.1
Disclosed:
Dec 14, 2011

CVE-2011-4803 on NVD →

WPtouch <= 1.9.8 - SQL Injection

high

SQL injection vulnerability in wptouch/ajax.php in the WPTouch plugin for WordPress allows remote attackers to execute arbitrary SQL commands via the id parameter.

CVSS:
7.3
Affected:
up to 1.9.8.1
Fixed in:
1.9.8.1
Disclosed:
Oct 27, 2011

CVE-2011-4803 on NVD →

WPtouch &#8211; Make your WordPress Website Mobile-Friendly [wptouch] < 1.9.3

unknown

This WordPress WPtouch plugin is prone to an URL redirection vulnerability.

Affected:
up to 1.9.3
Fixed in:
1.9.3
Disclosed:
Jun 21, 2011

WPtouch &#8211; Make your WordPress Website Mobile-Friendly [wptouch] < 1.9.20

unknown

[en] Cross-site scripting (XSS) vulnerability in lib/includes/auth.inc.php in the WPtouch plugin 1.9.19.4 and 1.9.20 for WordPress allows remote attackers to inject arbitrary web script or HTML via the wptouch_settings parameter to include/adsense-new.php. NOTE: some of these details are obtained from third party info...

Affected:
up to 1.9.20
Fixed in:
1.9.20
Disclosed:
Apr 7, 2011

CVE-2010-4779 on NVD →

WPtouch < 1.9.20 - Cross-Site Scripting

medium

Cross-site scripting (XSS) vulnerability in lib/includes/auth.inc.php in the WPtouch plugin 1.9.19.4 and 1.9.20 for WordPress allows remote attackers to inject arbitrary web script or HTML via the wptouch_settings parameter to include/adsense-new.php.

CVSS:
6.1
Affected:
up to 1.9.20
Fixed in:
1.9.20
Disclosed:
Dec 1, 2010

CVE-2010-4779 on NVD →

WPtouch &#8211; Make your WordPress Website Mobile-Friendly [wptouch] < 4.3.44

unknown

The plugin does not escape an URL before outputting it back in an attribute, leading to Reflected Cross-Site Scripting

Affected:
up to 4.3.44
Fixed in:
4.3.44

WPtouch &#8211; Make your WordPress Website Mobile-Friendly [wptouch] < 3.7.6

unknown

The WPtouch WordPress plugin was affected by a Cross-Site Scripting (XSS) security vulnerability.

Affected:
up to 3.7.6
Fixed in:
3.7.6

WPtouch &#8211; Make your WordPress Website Mobile-Friendly [wptouch] < 3.7

unknown

The WPtouch WordPress plugin was affected by an Unvalidated Open Redirect security vulnerability.

Affected:
up to 3.7
Fixed in:
3.7

WPtouch &#8211; Make your WordPress Website Mobile-Friendly [wptouch] < 1.9.30

unknown

The WPtouch WordPress plugin was affected by a &#039;wptouch_redirect&#039; Parameter URI Redirection security vulnerability.

Affected:
up to 1.9.30
Fixed in:
1.9.30

WPtouch &#8211; Make your WordPress Website Mobile-Friendly [wptouch] < 1.9.8.1

unknown

The WPtouch WordPress plugin was affected by an ajax/file_upload.php Crafted Content-Type File Upload Remote Code Execution security vulnerability.

Affected:
up to 1.9.8.1
Fixed in:
1.9.8.1

WPtouch &#8211; Make your WordPress Website Mobile-Friendly [wptouch] < 1.9.8.1

unknown

The WPtouch WordPress plugin was affected by an include/submit.php Multiple Parameter SQL Injection security vulnerability.

Affected:
up to 1.9.8.1
Fixed in:
1.9.8.1

WPtouch &#8211; Make your WordPress Website Mobile-Friendly [wptouch] < 3.4.3

unknown

The WPtouch WordPress plugin was affected by an Insecure Nonce Generation security vulnerability.

Affected:
up to 3.4.3
Fixed in:
3.4.3

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database