Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

wpmanageninja — Vulnerabilities & Security Advisories 19

Browse all 19 CVE security advisories affecting wpmanageninja. AI-powered Chinese analysis, POCs, and references for each vulnerability.

wpmanageninja is a WordPress management plugin designed to streamline website administration tasks. Historically, it has been associated with multiple critical vulnerabilities, including remote code execution (RCE), cross-site scripting (XSS), and privilege escalation issues. These vulnerabilities often stem from insufficient input validation and improper access controls. The plugin currently has three CVEs on record, highlighting ongoing security concerns. While no major public incidents have been widely documented, its vulnerability history suggests potential risks for unpatched installations. Users are advised to maintain updated versions and implement security best practices when using wpmanageninja to mitigate potential exploitation risks.

CVE ID Title CVSS Severity Published
CVE-2026-66633 WordPress Fluent Forms Pro Add On Pack plugin < 6.2.12 - Cross Site Scripting (XSS) vulnerability — Fluent Forms Pro Add On Pack CWE-79 7.1 High 2026-08-18
CVE-2026-73532 Fluent Forms Pro 6.2.7 Embedded Malicious Code via Tampered Plugin Build — Fluent Forms Pro CWE-506 9.8 Critical 2026-08-13
CVE-2026-73533 Ninja Tables Pro 5.2.11 Embedded Malicious Code via Tampered Plugin Build — Ninja Tables Pro CWE-506 9.8 Critical 2026-08-13
CVE-2026-66467 WordPress FluentCommunity plugin <= 2.7.5 - Cross Site Scripting (XSS) vulnerability — FluentCommunity CWE-79 6.5 Medium 2026-08-13
CVE-2026-18146 Fluent Forms <= 6.2.11 - Unauthenticated Stored Cross-Site Scripting via Notification Smartcode Values — Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder CWE-79 7.2 High 2026-08-13
CVE-2026-61964 WordPress Ninja Tables plugin <= 5.2.9 - Cross Site Scripting (XSS) vulnerability — Ninja Tables CWE-79 7.1 High 2026-08-06
CVE-2026-16636 FluentSMTP <= 2.2.95 - Unauthenticated Stored Cross-Site Scripting via Recipient Display Name (to.name) in Email Logs — FluentSMTP – WP SMTP Plugin with Amazon SES, SendGrid, Mailgun, Postmark, Cloudflare, toSend, Gmail and Any SMTP CWE-79 7.2 High 2026-08-06
CVE-2026-17571 Fluent Forms <= 6.2.8 - Reflected Cross-Site Scripting via 'param' — Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder CWE-79 6.1 Medium 2026-08-01
CVE-2026-17567 Fluent Forms <= 6.2.8 - Unauthenticated Sensitive Information Exposure via Insecure Direct Object Reference and Weak Transaction Hash in 'transaction' Parameter — Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder CWE-639 5.3 Medium 2026-07-31
CVE-2026-16655 Fluent Forms <= 6.2.7 - Unauthenticated Stored Cross-Site Scripting via Name Field Nested `password` Member — Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder CWE-79 7.2 High 2026-07-29
CVE-2026-15665 Fluent Support <= 2.3.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'redirect-to' Shortcode Attribute — Fluent Support – Helpdesk & Customer Support Ticket System CWE-79 6.4 Medium 2026-07-24
CVE-2026-65474 WordPress Ninja Tables plugin <= 5.2.10 - Sensitive Data Exposure vulnerability — Ninja Tables CWE-497 5.3 Medium 2026-07-23
CVE-2026-65470 WordPress Fluent Support plugin <= 2.3.0 - Cross Site Scripting (XSS) vulnerability — Fluent Support CWE-79 6.5 Medium 2026-07-23
CVE-2026-57715 WordPress Fluent CRM plugin <= 3.1.7 - Cross Site Scripting (XSS) vulnerability — Fluent CRM CWE-79 7.1 High 2026-07-13
CVE-2026-5069 Fluent Forms <= 6.2.1 - Incorrect Authorization to Authenticated (Subscriber+) Arbitrary Subscription Cancellation via 'subscription_id' — Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder CWE-863 5.4 Medium 2026-07-10
CVE-2026-42655 WordPress Best Payments Plugin for WP plugin <= 4.6.19 - Payment Bypass vulnerability — Best Payments Plugin for WP CWE-472 7.5 Medium 2026-06-15
CVE-2025-67971 WordPress FluentCart plugin < 1.3.0 - Cross Site Scripting (XSS) vulnerability — FluentCart CWE-79 7.1 High 2026-02-20
CVE-2025-13495 FluentCart A New Era of eCommerce <= 1.3.1 - Authenticated (Administrator+) SQL Injection via 'groupKey' Parameter — FluentCart A New Era of eCommerce – Faster, Lighter, and Simpler CWE-89 4.9 Medium 2025-12-03
CVE-2023-6953 PDF Generator For Fluent Forms <= 1.1.7 - Cross-Site Scripting — Fluent PDF Generator CWE-79 4.9 Medium 2024-02-05

This page lists every published CVE security advisory associated with wpmanageninja. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.