← WordPress Vulnerabilities
WordPress security by component

FULL – Cliente

FULL – Cliente is a WordPress component with 7 published CVE records in this archive. The latest tracked vulnerability was published May 02, 2025; the highest CVE/CNA score is 8.8.

Plugin slug: full-customer

CVE-2024-12023: FULL – Cliente: SQL injection

FULL – Cliente is affected by SQL injection. Exploitation requires at least subscriber-level access. A successful request can alter database queries and expose or modify WordPress data.

PublishedMay 02, 2025
Safe version guidanceSee mitigation notes
Safe version
May 02, 2025 CVE-2024-12023
FULL – Cliente: SQL injection
FULL – Cliente is affected by SQL injection. Exploitation requires at least subscriber-level access. A successful request can alter database queries and expose or modify WordPress data.
See mitigation notes
CVE6.5
NVDPending
Feb 22, 2025 CVE-2025-26757
FULL Customer: Filesystem traversal
FULL Customer is affected by filesystem traversal. Exposure depends on how the affected operation is made reachable by the site. A crafted path can escape the intended directory and reach files or directories elsewhere on the server.
See mitigation notes
CVE7.5
NVDPending
Dec 13, 2024 CVE-2024-54313
FULL Customer: Filesystem traversal
FULL Customer is affected by filesystem traversal. Exposure depends on how the affected operation is made reachable by the site. A crafted path can escape the intended directory and reach files or directories elsewhere on the server.
See mitigation notes
CVE6.5
NVDPending
Oct 11, 2024 CVE-2024-9211
FULL – Cliente: Cross-site scripting
FULL – Cliente is affected by cross-site scripting. The vulnerable path is reachable without authentication. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.1
NVDPending
Jul 11, 2024 CVE-2024-6447
FULL – Cliente: Cross-site scripting
FULL – Cliente is affected by cross-site scripting. The vulnerable path is reachable without authentication. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE7.2
NVDPending
Aug 09, 2023 CVE-2023-4243
site, granted they are packaged as a valid: Dangerous file upload
site, granted they are packaged as a valid is affected by dangerous file upload. Exploitation requires an authenticated WordPress account. Successful exploitation can place attacker-controlled executable content on the server and may lead to full site compromise.
See mitigation notes
CVE8.8
NVDPending
Aug 09, 2023 CVE-2023-4242
FULL - Customer: Sensitive information exposure
FULL - Customer is affected by sensitive information exposure. Exploitation requires an authenticated WordPress account. Successful exploitation can disclose data that should not be available to the caller.
See mitigation notes
CVE4.3
NVDPending