Known vulnerabilities in the Wpextended plugin
12 security advisories have been published for the Wpextended plugin. Each entry below states what an attacker can do, what privilege they need, and the version the issue was fixed in.
- Wpextended - Privilege Escalation (CVE-2026-4314) HIGH
- Wpextended - Cross-Site Scripting (XSS) (CVE-2025-4963) MEDIUM
- Wpextended - SQL Injection (CVE-2024-13184) HIGH
- Wpextended - Remote Code Execution (CVE-2024-11816) HIGH
- Wpextended - Cross-Site Scripting (XSS) (CVE-2024-9347) MEDIUM
- Wpextended - Security Vulnerability (CVE-2024-8123) MEDIUM
- Wpextended - Information Disclosure (CVE-2024-8106) MEDIUM
- Wpextended - Cross-Site Scripting (XSS) (CVE-2024-8119) MEDIUM
- Wpextended - Cross-Site Scripting (XSS) (CVE-2024-8117) MEDIUM
- Wpextended - Broken Access Control (CVE-2024-8121) MEDIUM
- Wpextended - Path Traversal (CVE-2024-8104) HIGH
- Wpextended - Privilege Escalation (CVE-2024-8102) HIGH