← WordPress Vulnerabilities
WordPress security by component

Community by PeepSo – Download from PeepSo.com

Community by PeepSo – Download from PeepSo.com is a WordPress component with 14 published CVE records in this archive. The latest tracked vulnerability was published Nov 21, 2024; the highest CVE/CNA score is 8.8.

Plugin slug: peepso-core

CVE-2024-11447: Community by PeepSo – Download from PeepSo.com: Cross-site scripting

Community by PeepSo – Download from PeepSo.com is affected by cross-site scripting. The vulnerable path is reachable without authentication. Injected script can execute in the affected site's origin when the vulnerable output is viewed.

PublishedNov 21, 2024
Safe version guidanceSee mitigation notes
Safe version
Nov 21, 2024 CVE-2024-11447
Community by PeepSo – Download from PeepSo.com: Cross-site scripting
Community by PeepSo – Download from PeepSo.com is affected by cross-site scripting. The vulnerable path is reachable without authentication. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.1
NVDPending
Sep 25, 2024 CVE-2024-7426
Community by PeepSo – Social Network, Membership, Registration, User Profiles: A security weakness
Community by PeepSo – Social Network, Membership, Registration, User Profiles is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE5.3
NVDPending
Sep 10, 2024 CVE-2024-7655
Community by PeepSo – Social Network, Membership, Registration, User Profiles: Cross-site scripting
Community by PeepSo – Social Network, Membership, Registration, User Profiles is affected by cross-site scripting. Exploitation requires at least administrator-level access. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE4.4
NVD4.8
Sep 10, 2024 CVE-2024-7618
Community by PeepSo – Social Network, Membership, Registration, User Profiles: Cross-site scripting
Community by PeepSo – Social Network, Membership, Registration, User Profiles is affected by cross-site scripting. Exploitation requires at least administrator-level access. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE4.4
NVD4.8
Apr 12, 2024 CVE-2024-31251
Community by PeepSo: Cross-site request forgery
Community by PeepSo is affected by cross-site request forgery. Exposure depends on how the affected operation is made reachable by the site. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
See mitigation notes
CVE4.3
NVDPending
Mar 28, 2024 CVE-2024-25923
Community by PeepSo: A security weakness
Community by PeepSo is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE5.3
NVDPending
Mar 26, 2024 CVE-2023-27630
Community by PeepSo: A security weakness
Community by PeepSo is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE5.3
NVDPending
Nov 30, 2023 CVE-2023-48746
Community by PeepSo – Social Network, Membership, Registration, User Profiles: Cross-site scripting
Community by PeepSo – Social Network, Membership, Registration, User Profiles is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE7.1
NVD6.1
Nov 30, 2023 CVE-2023-47850
Community by PeepSo – Social Network, Membership, Registration, User Profiles: Cross-site scripting
Community by PeepSo – Social Network, Membership, Registration, User Profiles is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.5
NVD5.4
Nov 22, 2023 CVE-2023-39925
Peepso Core: Cross-site request forgery
Peepso Core is affected by cross-site request forgery. Exposure depends on how the affected operation is made reachable by the site. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
See mitigation notes
CVE5.4
NVD8.8
Nov 09, 2023 CVE-2023-32092
Peepso Core: Cross-site request forgery
Peepso Core is affected by cross-site request forgery. Exposure depends on how the affected operation is made reachable by the site. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
See mitigation notes
CVE4.3
NVD8.8
May 03, 2023 CVE-2023-25967
Peepso Core: Cross-site request forgery
Peepso Core is affected by cross-site request forgery. Exposure depends on how the affected operation is made reachable by the site. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
See mitigation notes
CVE4.3
NVD8.8
Apr 04, 2023 CVE-2022-41633
Peepso Core: Cross-site request forgery
Peepso Core is affected by cross-site request forgery. Exposure depends on how the affected operation is made reachable by the site. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
See mitigation notes
CVE5.4
NVD8.8
Sep 16, 2019 CVE-2016-10968
Peepso Core: Privilege escalation or authentication bypass
Peepso Core is affected by privilege escalation or authentication bypass. Exposure depends on how the affected operation is made reachable by the site. A successful request can grant permissions or access that the caller should not possess.
See mitigation notes
CVE8.8
NVD8.8