cbcvebase.

Webandprint Ar For Wordpress vulnerabilities

4 known vulnerabilities affecting webandprint/ar_for_wordpress.

Total CVEs
4
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL2MEDIUM1LOW1

Vulnerabilities

Page 1 of 1
CVE-2024-50496P2CRITICALCVSS 10.0≤ 6.62024-10-28
CVE-2024-50496 [CRITICAL] CWE-434 CVE-2024-50496: Unrestricted Upload of File with Dangerous Type vulnerability in webandprint AR For WordPress ar-for Unrestricted Upload of File with Dangerous Type vulnerability in webandprint AR For WordPress ar-for-wordpress allows Upload a Web Shell to a Web Server.This issue affects AR For WordPress: from n/a through <= 6.6.
nvd
CVE-2025-60156P3CRITICALCVSS 9.6≤ 8.342025-09-26
CVE-2025-60156 [CRITICAL] CWE-352 CVE-2025-60156: Cross-Site Request Forgery (CSRF) vulnerability in webandprint AR For WordPress ar-for-wordpress all Cross-Site Request Forgery (CSRF) vulnerability in webandprint AR For WordPress ar-for-wordpress allows Upload a Web Shell to a Web Server.This issue affects AR For WordPress: from n/a through <= 8.34.
nvd
CVE-2025-26913P4MEDIUMCVSS 6.5≤ 7.72025-02-25
CVE-2025-26913 [MEDIUM] CWE-79 CVE-2025-26913: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability i Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in webandprint AR For WordPress ar-for-wordpress allows DOM-Based XSS.This issue affects AR For WordPress: from n/a through <= 7.7.
nvd
CVE-2024-12300P4LOWCVSS 3.7≤ 7.32024-12-13
CVE-2024-12300 [LOW] CWE-862 CVE-2024-12300: The AR for WordPress plugin for WordPress is vulnerable to unauthorized double extension file upload The AR for WordPress plugin for WordPress is vulnerable to unauthorized double extension file upload due to a missing capability check on the set_ar_featured_image() function in all versions up to, and including, 7.3. This makes it possible for unauthenticated attackers to upload php files leveraging a double extension attack. It's important to note th
nvd
Webandprint Ar For Wordpress vulnerabilities | cvebase