← WordPress Vulnerabilities
WordPress security by component

Malware Scanner

Malware Scanner is a WordPress component with 3 published CVE records in this archive. The latest tracked vulnerability was published Jun 04, 2024; the highest CVE/CNA score is 9.8.

Plugin slug: miniorange-malware-protection

CVE-2023-52176: Malware Scanner: Privilege escalation or authentication bypass

Malware Scanner is affected by privilege escalation or authentication bypass. Exposure depends on how the affected operation is made reachable by the site. A successful request can grant permissions or access that the caller should not possess.

PublishedJun 04, 2024
Safe version guidanceSee mitigation notes
Safe version
Jun 04, 2024 CVE-2023-52176
Malware Scanner: Privilege escalation or authentication bypass
Malware Scanner is affected by privilege escalation or authentication bypass. Exposure depends on how the affected operation is made reachable by the site. A successful request can grant permissions or access that the caller should not possess.
See mitigation notes
CVE5.3
NVDPending
Mar 13, 2024 CVE-2024-2172
Malware Scanner plugin and the Web Application Firewall: Privilege escalation or authentication bypass
Malware Scanner plugin and the Web Application Firewall is affected by privilege escalation or authentication bypass. The vulnerable path is reachable without authentication. A successful request can grant permissions or access that the caller should not possess.
See mitigation notes
CVE9.8
NVDPending
Feb 28, 2024 CVE-2024-25902
Malware Scanner: SQL injection
Malware Scanner is affected by SQL injection. Exposure depends on how the affected operation is made reachable by the site. A successful request can alter database queries and expose or modify WordPress data.
See mitigation notes
CVE7.6
NVD7.2