| CVE ID | Title | Vendor | Product | Severity | CVSS Score | Published At | AI Analysis |
|---|---|---|---|---|---|---|---|
| CVE-2024-43228 | WordPress SecuPress Free plugin <= 2.2.5.3 - Broken Access Control vulnerability | SecuPress | SecuPress Free | Medium | 5.3 | 2026-02-20 15:46:25 | Deep Dive |
| CVE-2025-3452 | SecuPress Free <= 2.3.9 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Plugin Installation | secupress | SecuPress with Simple SSL – Simple and Performant Security | Medium | 4.3 | 2025-04-29 08:21:44 | Deep Dive |
| CVE-2025-30907 | WordPress SecuPress Free plugin <= 2.2.5.3 - Cross Site Scripting (XSS) vulnerability | SecuPress | SecuPress Free | Medium | 6.5 | 2025-03-27 10:55:52 | Deep Dive |
| CVE-2024-9019 | SecuPress Free — WordPress Security <= 2.2.5.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via secupress_check_ban_ips_form Shortcode | secupress | SecuPress with Simple SSL – Simple and Performant Security | Medium | 6.4 | 2025-02-28 08:23:16 | Deep Dive |
| CVE-2024-1504 | SecuPress Free — WordPress Security <= 2.2.5.1 - Cross-Site Request Forgery to Banned IP Address | secupress | SecuPress with Simple SSL – Simple and Performant Security | Medium | 4.3 | 2024-04-02 05:32:50 | Deep Dive |