Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

Leyka — Vulnerabilities & Security Advisories 13

All 13 CVE vulnerabilities found in Leyka, with AI-generated Chinese analysis, references, and POCs.

This page documents Common Weakness Enumerations associated with the Leyka plugin for WordPress, focusing on security flaws within this specific content management system extension. It aggregates a comprehensive list of vulnerabilities that have been identified and publicly disclosed, covering incidents from early 2019 through the present day. By consolidating these records, the resource allows developers and security analysts to track advisory releases from the vendor over time, gain a deeper understanding of recurring weakness classes such as cross-site scripting or privilege escalation, and review the historical vulnerability landscape of the product. The data includes details on affected versions, severity ratings, and resolution status to facilitate risk assessment and patch management. This centralized view simplifies the process of monitoring the security posture of Leyka installations by providing a chronological record of defects that require attention. It serves as a reference point for system administrators who need to verify whether their specific version is impacted by known issues. The collection aims to provide transparency regarding the software’s development lifecycle and its response to security threats. Users can leverage this information to prioritize remediation efforts and ensure that their environments remain protected against previously exploited attack vectors. The scope includes both critical and low-severity issues to offer a complete picture of the plugin’s safety record. This information is intended for technical audiences responsible for maintaining WordPress-based websites that rely on this plugin.

Vendor: Teplitsa of social technologies

CVE ID Title CVSS Severity Published
CVE-2026-66677 WordPress Leyka plugin <= 3.32.3 - Broken Authentication vulnerability CWE-288 7.6 High 2026-08-20
CVE-2025-52805 WordPress Leyka plugin <= 3.32.1 - Local File Inclusion vulnerability CWE-35 7.5 High 2025-07-04
CVE-2025-53275 WordPress Leyka plugin <= 3.32.1 - Cross Site Scripting (XSS) vulnerability CWE-79 6.5 Medium 2025-06-27
CVE-2025-26766 WordPress Leyka plugin <= 3.31.8 - Cross Site Scripting (XSS) vulnerability CWE-79 6.5 Medium 2025-02-16
CVE-2024-49252 WordPress leyka plugin <=3.31.6 - Broken Access Control vulnerability CWE-497 5.3 Medium 2024-10-16
CVE-2024-35683 WordPress Leyka plugin <= 3.31.1 - Broken Access Control vulnerability CWE-862 5.3 Medium 2024-06-11
CVE-2023-33327 WordPress Leyka plugin <= 3.30.2 - Privilege Escalation vulnerability CWE-269 8.8 High 2024-05-14
CVE-2023-27442 WordPress Leyka Plugin <= 3.29.2 is vulnerable to Cross Site Request Forgery (CSRF) CWE-352 5.4 Medium 2023-11-22
CVE-2023-2995 Leyka < 3.30.4 - Admin+ Stored XSS 4.8 - 2023-09-19
CVE-2023-4917 Leyka <= 3.30.7 - Authenticated (Subscriber+) Sensitive Information Exposure CWE-200 5.3 Medium 2023-09-13
CVE-2023-33325 WordPress Leyka Plugin <= 3.30.1 is vulnerable to Cross Site Scripting (XSS) CWE-79 7.1 High 2023-08-30
CVE-2023-39314 WordPress Leyka Plugin <= 3.30.2 is vulnerable to Cross Site Scripting (XSS) CWE-79 7.1 High 2023-08-10
CVE-2023-27450 WordPress Leyka Plugin <= 3.29.2 is vulnerable to Cross Site Scripting (XSS) CWE-79 7.1 High 2023-06-21

All 13 known CVE vulnerabilities affecting Leyka with full Chinese analysis, references, and POCs where available.