Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

WPChill — Vulnerabilities & Security Advisories 65

Browse all 65 CVE security advisories affecting WPChill. AI-powered Chinese analysis, POCs, and references for each vulnerability.

WPChill operates as a developer of premium WordPress plugins, primarily focusing on e-commerce solutions, membership management, and digital product delivery. Security audits reveal a concerning history, with 57 recorded Common Vulnerabilities and Exposures (CVEs) associated with its software portfolio. These vulnerabilities predominantly stem from insufficient input validation and inadequate access controls, leading to frequent instances of Remote Code Execution (RCE), Cross-Site Scripting (XSS), and Privilege Escalation. Many flaws allow unauthenticated attackers to execute arbitrary code or manipulate administrative functions, highlighting systemic weaknesses in code review processes. While the company provides technical support, the high volume of disclosed CVEs suggests a reactive rather than proactive security posture. Users of WPChill products face significant risk, necessitating rigorous patch management and continuous monitoring to mitigate potential exploitation of these historically common attack vectors.

CVE ID Title CVSS Severity Published
CVE-2026-100182 Download Monitor <= 5.2.10 - Unauthenticated Stored Cross-Site Scripting via Cross-Origin postMessage to Admin Editor — Download Monitor CWE-79 7.2 High 2026-10-02
CVE-2026-89406 Modula Image Gallery <= 3.0.1 - Missing Authorization to Unauthenticated Private Gallery Image Disclosure via 'modula_gallery_id' and 'modula_image_id' Parameters — Modula Image Gallery – Photo Grid & Video Gallery CWE-862 7.5 High 2026-09-25
CVE-2026-92713 Modula Image Gallery <= 3.0.2 - Missing Authorization to Authenticated (Author+) Arbitrary File Deletion (Non-PHP) via 'file' Parameter — Modula Image Gallery – Photo Grid & Video Gallery CWE-862 8.1 High 2026-09-25
CVE-2026-92622 Strong Testimonials <= 3.3.8 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'lightbox_class' Shortcode Attribute — Strong Testimonials CWE-79 6.4 Medium 2026-09-18
CVE-2026-4559 Image Photo Gallery Final Tiles Grid <= 3.6.12 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'delay' Shortcode Attribute — Image Photo Gallery Final Tiles Grid CWE-79 6.4 Medium 2026-08-22
CVE-2026-16144 Kali Forms <= 2.4.20 - Unauthenticated Remote Code Execution via 'thisPermalink' Field Parameter — Kali Forms — Contact Form & Drag-and-Drop Builder CWE-94 8.1 High 2026-08-01
CVE-2026-15395 Kali Forms <= 2.4.18 - Unauthenticated Stored Cross-Site Scripting via 'digitalSignature' Field Value — Kali Forms — Contact Form & Drag-and-Drop Builder CWE-79 7.2 High 2026-07-17
CVE-2026-9107 Kali Forms <= 2.4.13 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'kaliforms_field_components' Parameter — Kali Forms — Contact Form & Drag-and-Drop Builder CWE-79 6.4 Medium 2026-07-01
CVE-2026-3239 Strong Testimonials <= 3.2.21 - Authenticated (Contributor+) Stored Cross-Site Scripting via testimonial_view Shortcode — Strong Testimonials CWE-79 6.4 Medium 2026-04-08
CVE-2026-4401 Download Monitor <= 5.1.10 - Cross-Site Request Forgery to Download Path Deletion and Disabling — Download Monitor CWE-352 5.4 Medium 2026-04-07
CVE-2026-3124 Download Monitor <= 5.1.7 - Insecure Direct Object Reference to Unauthenticated Arbitrary Order Completion via 'token' and 'order_id' — Download Monitor CWE-639 7.5 High 2026-03-30
CVE-2026-3584 Kali Forms <= 2.4.9 - Unauthenticated Remote Code Execution via form_process — Kali Forms — Contact Form & Drag-and-Drop Builder CWE-94 9.8 Critical 2026-03-20
CVE-2026-1860 Kali Forms <= 2.4.8 - Insecure Direct Object Reference to Authenticated (Contributor+) Sensitive Form Data Exposure — Kali Forms — Contact Form & Drag-and-Drop Builder CWE-862 4.3 Medium 2026-02-18
CVE-2026-1254 Modula Image Gallery – Photo Grid & Video Gallery <= 2.13.6 - Missing Authorization to Authenticated (Contributor+) Arbitrary Post/Page Editing — Modula Image Gallery – Photo Grid & Video Gallery CWE-862 4.3 Medium 2026-02-14
CVE-2025-14865 Passster – Password Protect Pages and Content <= 4.2.24 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode — Passster – Password Protect Pages and Content CWE-79 6.4 Medium 2026-01-28
CVE-2025-15466 Image Photo Gallery Final Tiles Grid <= 3.6.9 - Missing Authorization to Authenticated (Contributor+) Arbitrary Gallery Management — Image Photo Gallery Final Tiles Grid CWE-862 5.4 Medium 2026-01-19
CVE-2025-14632 Filr – Secure document library <= 1.2.11 - Authenticated (Administrator+) Stored Cross-Site Scripting via HTML Upload — Filr – Secure document library CWE-434 4.4 Medium 2026-01-17
CVE-2025-14426 Strong Testimonials <= 3.2.18 - Missing Authorization to Authenticated (Contributor+) Rating Meta Update — Strong Testimonials CWE-862 4.3 Medium 2025-12-30
CVE-2025-13693 Image Photo Gallery Final Tiles Grid <= 3.6.8 - Authenticated (Author+) Stored Cross-Site Scripting via 'Custom Scripts' Setting — Image Photo Gallery Final Tiles Grid CWE-79 6.4 Medium 2025-12-21
CVE-2025-14455 Image Photo Gallery Final Tiles Grid <= 3.6.7 - Missing Authorization to Authenticated (Contributor+) Gallery Management — Image Photo Gallery Final Tiles Grid CWE-862 5.4 Medium 2025-12-19
CVE-2025-14003 Image Gallery – Photo Grid & Video Gallery <= 2.13.3 - Missing Authorization to Authenticated (Author+) Arbitrary Gallery Modification — Modula Image Gallery – Photo Grid & Video Gallery CWE-862 4.3 Medium 2025-12-15
CVE-2025-13891 Image Gallery – Photo Grid & Video Gallery (Modula) <= 2.13.3 - Missing Authorization to Arbitrary Directory Listing — Modula Image Gallery – Photo Grid & Video Gallery CWE-22 6.5 Medium 2025-12-12
CVE-2025-13646 Modula 2.13.1 - 2.13.2 - Authenticated (Author+) Arbitrary File Upload via Race Condition — Image Gallery – Photo Grid & Video Gallery CWE-434 7.5 High 2025-12-03
CVE-2025-13645 Modula 2.13.1 - 2.13.2 - Authenticated (Author+) Arbitrary File Deletion — Image Gallery – Photo Grid & Video Gallery CWE-22 7.2 High 2025-12-03
CVE-2025-12494 Image Gallery – Photo Grid & Video Gallery <= 2.12.28 - Improper Authorization to Authenticated (Author+) Arbitrary Image File Move — Modula Image Gallery – Photo Grid & Video Gallery CWE-285 4.3 Medium 2025-11-15
CVE-2025-11268 Strong Testimonials <= 3.2.16 - Unauthenticated Arbitrary Shortcode Execution — Strong Testimonials CWE-79 4.3 Medium 2025-11-06
CVE-2025-10000 Qyrr – simply and modern QR-Code creation <= 2.0.7 - Authenticated (Contributor+) Arbitrary File Upload — Qyrr – simply and modern QR-Code creation CWE-434 6.4 Medium 2025-09-30
CVE-2025-7367 Strong Testimonials <= 3.2.11 - Authenticated (Author+) Stored Cross-Site Scripting via Custom Fields — Strong Testimonials CWE-79 6.4 Medium 2025-07-15
CVE-2024-9416 Modula Image Gallery <= 2.10.1 - Authenticated (Contributor+) Stored DOM-Based Cross-Site Scripting via FancyBox 5 JavaScript Library — Modula Image Gallery – Photo Grid & Video Gallery CWE-79 6.4 Medium 2025-04-03
CVE-2024-6261 Image Photo Gallery Final Tiles Grid <= 3.6.0 - Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting — Image Photo Gallery Final Tiles Grid CWE-79 6.4 Medium 2025-02-27

This page lists every published CVE security advisory associated with WPChill. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.