wpcerber CVE Vulnerabilities & CVE List (4)

Products (CPE): — CVEs: 4

wpcerber vulnerability overview

Aggregates CVE and security vulnerability intelligence across all wpcerber-related products, including CVSS, EPSS, publication dates, and vulnerability intelligence data.

Disclosed issues often relate to vendor risk cross-site scripting; exposure may include vendor impact session compromise in vendor surface production workloads and vendor surface software deployment contexts.

Vulnerability distribution trend (last 24 months)

Showing 14 of 4 CVEs
«« First « Prev Page 1 / 1 Next »
CVE Summary Source Max CVSS EPSS % Published Updated
CVE-2022-4100 The WP Cerber Security plugin for WordPress is vulnerable to IP Protection bypass in versions up to, and including 9.4 due to the plugin improperly checking for a visitor's IP address. This makes it possible for an attacker whose IP address has been blocked to bypass this control by setting the X-Forwarded-For: HTTP header to an IP Address that hasn't been blocked. [email protected] 5.3 0.35% 2024-08-31 2026-06-17
CVE-2021-37598 WP Cerber before 8.9.3 allows bypass of /wp-json access control via a trailing ? character. [email protected] 5.3 2.37% 2021-08-19 2026-06-17
CVE-2021-37597 WP Cerber before 8.9.3 allows MFA bypass via wordpress_logged_in_[hash] manipulation. [email protected] 9.8 2.12% 2021-08-19 2026-06-17
CVE-2016-10990 The wp-cerber plugin before 2.7 for WordPress has XSS via the X-Forwarded-For HTTP header. [email protected] 6.1 1.42% 2019-09-17 2026-06-16
«« First « Prev Page 1 / 1 Next »
cvelogic Threat Intelligence