← WordPress Vulnerabilities
WordPress security by component

GigPress

GigPress is a WordPress component with 6 published CVE records in this archive. The latest tracked vulnerability was published Feb 12, 2024; the highest CVE/CNA score is 8.8.

Plugin slug: gigpress

CVE-2023-7233: GigPress: Cross-site scripting

GigPress is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.

PublishedFeb 12, 2024
Safe version guidanceSee mitigation notes
Safe version
Feb 12, 2024 CVE-2023-7233
GigPress: Cross-site scripting
GigPress is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE4.8
NVD4.8
Feb 27, 2023 CVE-2023-0381
GigPress: SQL injection
GigPress is affected by SQL injection. Exposure depends on how the affected operation is made reachable by the site. A successful request can alter database queries and expose or modify WordPress data.
See mitigation notes
CVE8.8
NVD8.8
Feb 13, 2023 CVE-2022-4759
GigPress: Cross-site scripting
GigPress is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.8
NVD5.4
Aug 28, 2019 CVE-2015-9354
Gigpress: Cross-site scripting
Gigpress is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE4.8
NVD4.8
Aug 28, 2019 CVE-2015-9353
Gigpress: SQL injection
Gigpress is affected by SQL injection. Exposure depends on how the affected operation is made reachable by the site. A successful request can alter database queries and expose or modify WordPress data.
See mitigation notes
CVE7.2
NVD7.2
May 27, 2015 CVE-2015-4066
Gigpress: SQL injection
Gigpress is affected by SQL injection. Exposure depends on how the affected operation is made reachable by the site. A successful request can alter database queries and expose or modify WordPress data.
See mitigation notes
CVE6.5
NVD6.5