WordPress security by component
Content Mask
Plugin description
Content Mask is a WordPress component with 3 published CVE records in this archive. The latest tracked vulnerability was published Sep 22, 2025; the highest published CVSS base score is 6.4.
Plugin slug:
content-maskLatest vulnerability
CVE-2025-58012: Content Mask: A security weakness
Content Mask is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.
| Safe version |
|
||
|---|---|---|---|
| Sep 22, 2025 |
CVE-2025-58012
Content Mask: A security weakness
Content Mask is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.
|
See mitigation notes |
CVE3.8
NVDPending
|
| Sep 22, 2025 |
CVE-2025-58011
Content Mask: Server-side request forgery
Content Mask is affected by server-side request forgery. Exposure depends on how the affected operation is made reachable by the site. The vulnerable server can be induced to make attacker-selected network requests. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.
|
See mitigation notes |
CVE6.4
NVDPending
|
| May 30, 2022 |
CVE-2022-1203
Content Mask: Cross-site request forgery
Content Mask is affected by cross-site request forgery. Exposure depends on how the affected operation is made reachable by the site. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.
|
See mitigation notes |
CVEPending
NVD4.3
|