WordPress security by component
Nelio Content
Plugin description
Nelio Content is a WordPress component with 5 published CVE records in this archive. The latest tracked vulnerability was published Jun 26, 2026; the highest CVE/CNA score is 8.5.
Plugin slug:
nelio-contentLatest vulnerability
CVE-2026-57648: Nelio Content: A security weakness
Nelio Content is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is n/a through 4.3.4.
| Safe version |
|
||
|---|---|---|---|
| Jun 26, 2026 |
CVE-2026-57648
Nelio Content: A security weakness
Nelio Content is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is n/a through 4.3.4.
|
4.3.5 |
CVE4.3
NVDPending
|
| Apr 08, 2026 |
CVE-2026-39521
Nelio Content: Server-side request forgery
Nelio Content is affected by server-side request forgery. Exposure depends on how the affected operation is made reachable by the site. The vulnerable server can be induced to make attacker-selected network requests. The published affected range is <= 4.3.1.
|
4.3.2 |
CVE4.9
NVDPending
|
| Jan 23, 2026 |
CVE-2026-24572
Nelio Content: SQL injection
Nelio Content is affected by SQL injection. Exposure depends on how the affected operation is made reachable by the site. A successful request can alter database queries and expose or modify WordPress data.
|
See mitigation notes |
CVE8.5
NVDPending
|
| Oct 27, 2025 |
CVE-2025-62927
Nelio Content: A security weakness
Nelio Content is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE6.5
NVDPending
|
| Apr 02, 2024 |
CVE-2024-30531
Nelio Content: Server-side request forgery
Nelio Content is affected by server-side request forgery. Exposure depends on how the affected operation is made reachable by the site. The vulnerable server can be induced to make attacker-selected network requests.
|
See mitigation notes |
CVE4.9
NVDPending
|