Vulnerabilities > Matbao

DATE CVE VULNERABILITY TITLE RISK
2024-10-10 CVE-2024-9065 Missing Authorization vulnerability in Matbao WP Helper Premium
The WP Helper Premium plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'whp_smtp_send_mail_test' function in all versions up to, and including, 4.6.1.
network
low complexity
matbao CWE-862
5.3
2023-11-09 CVE-2023-46614 Cross-Site Request Forgery (CSRF) vulnerability in Matbao WP Helper Premium
Cross-Site Request Forgery (CSRF) vulnerability in Mat Bao Corp WP Helper Premium plugin <= 4.5.1 versions.
network
low complexity
matbao CWE-352
8.8
2023-01-26 CVE-2023-0448 Cross-site Scripting vulnerability in Matbao WP Helper Premium
The WP Helper Lite WordPress plugin, in versions < 4.3, returns all GET parameters unsanitized in the response, resulting in a reflected cross-site scripting vulnerability.
network
low complexity
matbao CWE-79
6.1