Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total5
Critical1
High3
Medium1
Reset
Showing 1-5 of 5 records
Threat Entry Updated 2025-12-08

CVE-2025-13144 - Contentstudio Plugin

The ContentStudio plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.3.7. This is due to missing or insufficient nonce validation on the add_cstu_settings function. This makes it possible for unauthenticated attackers to modify plugin settings via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

PLUGIN Contentstudio

CVE-2025-13144

MEDIUM CVSS 4.3 2025-12-05
Threat Entry Updated 2025-12-08

CVE-2025-12181 - Contentstudio Plugin

The ContentStudio plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the cstu_update_post() function in all versions up to, and including, 1.3.7. This makes it possible for authenticated attackers, with Author-level access and above, to upload arbitrary files on the affected site's server which may make remote code execution possible.

PLUGIN Contentstudio

CVE-2025-12181

HIGH CVSS 8.8 2025-12-05
Threat Entry Updated 2024-11-21

CVE-2023-0556 - Contentstudio Plugin

The ContentStudio plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on several functions in versions up to, and including, 1.2.5. This makes it possible for unauthenticated attackers to obtain the blog metadata (via the function cstu_get_metadata) that includes the plugin's contentstudio_token. Knowing this token allows for other interactions with the plugin such as creating posts in versions prior to 1.2.5, which added other requirements to posting and updating.

PLUGIN Contentstudio

CVE-2023-0556

CRITICAL CVSS 9.8 2023-01-27
Threat Entry Updated 2024-11-21

CVE-2023-0558 - Contentstudio Plugin

The ContentStudio plugin for WordPress is vulnerable to authorization bypass due to an unsecure token check that is susceptible to type juggling in versions up to, and including, 1.2.5. This makes it possible for unauthenticated attackers to execute functions intended for use by users with proper API keys.

PLUGIN Contentstudio

CVE-2023-0558

HIGH CVSS 8.2 2023-01-27
Threat Entry Updated 2024-11-21

CVE-2023-0557 - Contentstudio Plugin

The ContentStudio plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 1.2.5. This could allow unauthenticated attackers to obtain a nonce needed for the creation of posts.

PLUGIN Contentstudio

CVE-2023-0557

HIGH CVSS 7.5 2023-01-27
Scroll to top