← WordPress Vulnerabilities
WordPress security by component

WebinarPress

WebinarPress is a WordPress component with 7 published CVE records in this archive. The latest tracked vulnerability was published Oct 27, 2025; the highest CVE/CNA score is 8.8.

Plugin slug: webinarpress

CVE-2025-62972: WebinarPress: A security weakness

WebinarPress is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.

PublishedOct 27, 2025
Safe version guidanceSee mitigation notes
Safe version
Oct 27, 2025 CVE-2025-62972
WebinarPress: A security weakness
WebinarPress is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE4.3
NVDPending
May 07, 2025 CVE-2025-47635
WebinarPress: Server-side request forgery
WebinarPress is affected by server-side request forgery. Exposure depends on how the affected operation is made reachable by the site. The vulnerable server can be induced to make attacker-selected network requests.
See mitigation notes
CVE5.5
NVD9.8
Apr 09, 2025 CVE-2025-32693
WebinarPress: An open redirect
WebinarPress is affected by an open redirect. Exposure depends on how the affected operation is made reachable by the site. A crafted link can redirect visitors from the trusted site to an attacker-controlled destination.
See mitigation notes
CVE4.7
NVDPending
Apr 01, 2025 CVE-2025-31883
WebinarPress: Cross-site scripting
WebinarPress is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE5.9
NVD4.8
Apr 01, 2025 CVE-2025-31882
WebinarPress: A security weakness
WebinarPress is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE4.3
NVDPending
Jan 08, 2025 CVE-2024-11271
WordPress Webinar Plugin – WebinarPress: A security weakness
WordPress Webinar Plugin – WebinarPress is affected by a security weakness. Exploitation requires at least subscriber-level access. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE8.8
NVD4.3
Jan 08, 2025 CVE-2024-11270
WordPress Webinar Plugin – WebinarPress: Code execution
WordPress Webinar Plugin – WebinarPress is affected by code execution. Exploitation requires at least subscriber-level access. Successful exploitation can run attacker-controlled code in the WordPress hosting account.
See mitigation notes
CVE8.8
NVDPending