← WordPress Vulnerabilities
WordPress security by component

MoveTo

MoveTo is a WordPress component with 4 published CVE records in this archive. The latest tracked vulnerability was published Apr 16, 2024; the highest CVE/CNA score is 10.

Plugin slug: moveto

CVE-2024-25911: MoveTo: A security weakness

MoveTo is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.

PublishedApr 16, 2024
Safe version guidanceSee mitigation notes
Safe version
Apr 16, 2024 CVE-2024-25911
MoveTo: A security weakness
MoveTo is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE8.6
NVDPending
Apr 11, 2024 CVE-2024-25912
MoveTo: A security weakness
MoveTo is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE9.8
NVDPending
Feb 28, 2024 CVE-2024-25910
MoveTo: SQL injection
MoveTo is affected by SQL injection. Exposure depends on how the affected operation is made reachable by the site. A successful request can alter database queries and expose or modify WordPress data.
See mitigation notes
CVE9.8
NVD9.8
Feb 26, 2024 CVE-2024-25913
MoveTo: Dangerous file upload
MoveTo is affected by dangerous file upload. Exposure depends on how the affected operation is made reachable by the site. Successful exploitation can place attacker-controlled executable content on the server and may lead to full site compromise.
See mitigation notes
CVE10.0
NVD9.8