Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

wpmanageninja — Vulnerabilities & Security Advisories 19

Browse all 19 CVE security advisories affecting wpmanageninja. AI-powered Chinese analysis, POCs, and references for each vulnerability.

wpmanageninja is a WordPress management plugin designed to streamline website administration tasks. Historically, it has been associated with multiple critical vulnerabilities, including remote code execution (RCE), cross-site scripting (XSS), and privilege escalation issues. These vulnerabilities often stem from insufficient input validation and improper access controls. The plugin currently has three CVEs on record, highlighting ongoing security concerns. While no major public incidents have been widely documented, its vulnerability history suggests potential risks for unpatched installations. Users are advised to maintain updated versions and implement security best practices when using wpmanageninja to mitigate potential exploitation risks.

Found 5 results / 19 Clear Filters
CVE ID Title CVSS Severity Published
CVE-2026-18146 Fluent Forms <= 6.2.11 - Unauthenticated Stored Cross-Site Scripting via Notification Smartcode Values — Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder CWE-79 7.2 High 2026-08-13
CVE-2026-17571 Fluent Forms <= 6.2.8 - Reflected Cross-Site Scripting via 'param' — Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder CWE-79 6.1 Medium 2026-08-01
CVE-2026-17567 Fluent Forms <= 6.2.8 - Unauthenticated Sensitive Information Exposure via Insecure Direct Object Reference and Weak Transaction Hash in 'transaction' Parameter — Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder CWE-639 5.3 Medium 2026-07-31
CVE-2026-16655 Fluent Forms <= 6.2.7 - Unauthenticated Stored Cross-Site Scripting via Name Field Nested `password` Member — Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder CWE-79 7.2 High 2026-07-29
CVE-2026-5069 Fluent Forms <= 6.2.1 - Incorrect Authorization to Authenticated (Subscriber+) Arbitrary Subscription Cancellation via 'subscription_id' — Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder CWE-863 5.4 Medium 2026-07-10

This page lists every published CVE security advisory associated with wpmanageninja. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.