← WordPress Vulnerabilities
WordPress security by component

WP Tools

WP Tools is a WordPress component with 4 published CVE records in this archive. The latest tracked vulnerability was published Jun 06, 2025; the highest CVE/CNA score is 8.8.

Plugin slug: wptools

CVE-2025-49273: WP Tools: Cross-site request forgery

WP Tools is affected by cross-site request forgery. Exposure depends on how the affected operation is made reachable by the site. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.

PublishedJun 06, 2025
Safe version guidanceSee mitigation notes
Safe version
Jun 06, 2025 CVE-2025-49273
WP Tools: Cross-site request forgery
WP Tools is affected by cross-site request forgery. Exposure depends on how the affected operation is made reachable by the site. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
See mitigation notes
CVE4.3
NVDPending
Apr 16, 2025 CVE-2025-39544
WP Tools: Filesystem traversal
WP Tools is affected by filesystem traversal. Exposure depends on how the affected operation is made reachable by the site. A crafted path can escape the intended directory and reach files or directories elsewhere on the server.
See mitigation notes
CVE7.4
NVDPending
Jun 21, 2024 CVE-2022-43453
WP Tools: A security weakness
WP Tools is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE8.8
NVD8.8
Dec 12, 2022 CVE-2022-3881
WP Tools Increase Maximum Limits, Repair, Server PHP Info, Javascript errors, File Permissions, Transients, Error Log: Cross-site request forgery
WP Tools Increase Maximum Limits, Repair, Server PHP Info, Javascript errors, File Permissions, Transients, Error Log is affected by cross-site request forgery. Exposure depends on how the affected operation is made reachable by the site. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
See mitigation notes
CVE5.7
NVD5.7