WordPress security by component
Nelio AB Testing
Plugin description
Nelio AB Testing is a WordPress component with 8 published CVE records in this archive. The latest tracked vulnerability was published Apr 15, 2026; the highest CVE/CNA score is 10.
Plugin slug:
nelio-ab-testingLatest vulnerability
CVE-2026-40742: Nelio AB Testing: A security weakness
Nelio AB Testing is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is <= 8.2.8.
| Safe version |
|
||
|---|---|---|---|
| Apr 15, 2026 |
CVE-2026-40742
Nelio AB Testing: A security weakness
Nelio AB Testing is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is <= 8.2.8.
|
8.3.0 |
CVE5.3
NVDPending
|
| Mar 25, 2026 |
CVE-2026-32573
Nelio AB Testing: Code execution
Nelio AB Testing is affected by code execution. Exposure depends on how the affected operation is made reachable by the site. Successful exploitation can run attacker-controlled code in the WordPress hosting account. The published affected range is n/a through <= 8.2.7.
|
8.2.8 |
CVE9.1
NVDPending
|
| Feb 19, 2026 |
CVE-2026-25378
Nelio AB Testing: SQL injection
Nelio AB Testing is affected by SQL injection. Exposure depends on how the affected operation is made reachable by the site. A successful request can alter database queries and expose or modify WordPress data.
|
See mitigation notes |
CVE7.6
NVDPending
|
| Jan 22, 2026 |
CVE-2025-67944
Nelio AB Testing: Code execution
Nelio AB Testing is affected by code execution. Exposure depends on how the affected operation is made reachable by the site. Successful exploitation can run attacker-controlled code in the WordPress hosting account.
|
See mitigation notes |
CVE9.1
NVDPending
|
| Sep 17, 2019 |
CVE-2016-10977
Nelio Ab Testing: Filesystem traversal
Nelio Ab Testing is affected by filesystem traversal. Exposure depends on how the affected operation is made reachable by the site. A crafted path can escape the intended directory and reach files or directories elsewhere on the server.
|
See mitigation notes |
CVE6.5
NVD6.5
|
| Aug 22, 2019 |
CVE-2016-10927
Nelio Ab Testing: Server-side request forgery
Nelio Ab Testing is affected by server-side request forgery. Exposure depends on how the affected operation is made reachable by the site. The vulnerable server can be induced to make attacker-selected network requests.
|
See mitigation notes |
CVE10.0
NVD10.0
|
| Aug 22, 2019 |
CVE-2016-10926
Nelio Ab Testing: Server-side request forgery
Nelio Ab Testing is affected by server-side request forgery. Exposure depends on how the affected operation is made reachable by the site. The vulnerable server can be induced to make attacker-selected network requests.
|
See mitigation notes |
CVE10.0
NVD10.0
|
| Aug 16, 2019 |
CVE-2017-18547
Nelio Ab Testing: Cross-site request forgery
Nelio Ab Testing is affected by cross-site request forgery. Exposure depends on how the affected operation is made reachable by the site. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
|
See mitigation notes |
CVE8.8
NVD8.8
|