{"error":0,"message":null,"data":{"name":"ManageWP Worker","plugin":"worker","link":"https:\/\/wordpress.org\/plugins\/worker\/","latest":"1787293260","closed":0,"closed_reason":null,"closed_date":null,"vulnerability":[{"uuid":"37c0f3846c9e27eb8f306e6009ff7c9a0893157233416016489ca48782d32560","name":"ManageWP Worker [worker] < 4.9.3","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"4.9.3","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"789a6ab801477af9ad5fe7f355a0f14114bd6d5f","name":"Manage WP Worker <= 4.9.2 - Authentication Bypass","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/worker\/manage-wp-worker-492-authentication-bypass","description":"The Manage WP Worker plugin for WordPress is vulnerable to authentication bypass in versions up to, and including 4.9.2, due to the use of global keys that every installation of Manage WP worker uses for signature verification. This makes it possible to specially craft a request that can be used to auto-login as any user on any WordPress site running the plugin.","date":"2020-02-11"}],"impact":[]},{"uuid":"43a2206e5421594c3b86ed467c24325fd34bd3f6f057b51f6d5ae0be6ffcd071","name":"ManageWP Worker [worker] < 4.9.32","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"4.9.32","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2026-39463","name":"CVE-2026-39463","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2026-39463","description":"[en] Unauthenticated Cross Site Scripting (XSS) in ManageWP Worker <= 4.9.31 versions.","date":"2026-06-15"},{"id":"7788d3c0ef5bb6debabe6716ceb0d2cfc9e637d1","name":"ManageWP Worker <= 4.9.31 - Unauthenticated Stored Cross-Site Scripting","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/worker\/managewp-worker-4931-unauthenticated-stored-cross-site-scripting","description":"The ManageWP Worker plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 4.9.31 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":"2026-04-13"},{"id":"EUVD-2026-36931","name":"EUVD-2026-36931","link":"https:\/\/euvd.enisa.europa.eu\/enisa\/EUVD-2026-36931","description":"Unauthenticated Cross Site Scripting (XSS) in ManageWP Worker <= 4.9.31 versions.","date":"2026-06-15"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:R\/S:C\/C:L\/I:L\/A:L","av":"n","ac":"l","pr":"n","ui":"r","s":"c","c":"l","i":"l","a":"l","score":"7.1","severity":"h","exploitable":"0.0","impact":"0.0"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:R\/S:C\/C:L\/I:L\/A:L","score":"7.1","severity":"high","av":"network","ac":"low","pr":"none","ui":"required","s":"changed","c":"low","i":"low","a":"low","exploitable":"0.0","impact":"0.0"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"9d709729cfff542e1b559ce1291eb5a1b0b6541040f01f664ae479212d5ed383","name":"ManageWP Worker [worker] < 4.9.32","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"4.9.32","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2026-3718","name":"CVE-2026-3718","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2026-3718","description":"[en] The ManageWP Worker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'MWP-Key-Name' HTTP request header in all versions up to, and including, 4.9.31. This is due to insufficient input sanitization and output escaping of attacker-controlled header values. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever an administrator visits the plugin's connection management page with debug parameters.","date":"2026-05-14"},{"id":"4c83183430651e3d1c215e8b65951d69cc3e21a0","name":"WordPress ManageWP Worker Plugin <= 4.9.31 is vulnerable to a medium priority Cross Site Scripting (XSS)","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/worker\/vulnerability\/wordpress-managewp-worker-plugin-4-9-31-unauthenticated-stored-cross-site-scripting-vulnerability","description":"<p>WordPress ManageWP Worker Plugin <= 4.9.31 is vulnerable to a medium priority Cross Site Scripting (XSS)<\/p><p>Software: ManageWP Worker<\/p><p>Fixed in version 4.9.32 <\/p><p>Affected Version <= 4.9.31<\/p><p>CVE: CVE-2026-3718<\/p>","date":"2026-05-14"},{"id":"f80633e7119c437ec498008a088e764b41de0ae0","name":"ManageWP Worker <= 4.9.31 - Unauthenticated Stored Cross-Site Scripting via 'MWP-Key-Name' Header","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/worker\/managewp-worker-4931-unauthenticated-stored-cross-site-scripting-via-mwp-key-name-header","description":"The ManageWP Worker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'MWP-Key-Name' HTTP request header in all versions up to, and including, 4.9.31. This is due to insufficient input sanitization and output escaping of attacker-controlled header values. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever an administrator visits the plugin's connection management page with debug parameters.","date":"2026-05-13"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:C\/C:L\/I:L\/A:N","av":"n","ac":"l","pr":"n","ui":"n","s":"c","c":"l","i":"l","a":"n","score":"7.2","severity":"h","exploitable":"0.0","impact":"0.0"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:C\/C:L\/I:L\/A:N","score":"7.2","severity":"high","av":"network","ac":"low","pr":"none","ui":"none","s":"changed","c":"low","i":"low","a":"none","exploitable":"0.0","impact":"0.0"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}],"ssvc":{"exploitation":"none","automatable":"yes","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"0aa917bc3dd6059fff463cb8813c49fe0f3f9178b87388c71b3d07932dad24a3","name":"ManageWP Worker [worker] < 4.9.37","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"4.9.37","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2026-18052","name":"CVE-2026-18052","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2026-18052","description":"[en] The ManageWP Worker WordPress plugin before 4.9.37 does not bind the account being logged in to the signature which authorises the login, nor prevent an already used login link from being replayed, allowing attackers who obtain such a link to gain a session as any user on the site, including an administrator.","date":"2026-08-22"},{"id":"EUVD-2026-64219","name":"EUVD-2026-64219","link":"https:\/\/euvd.enisa.europa.eu\/enisa\/EUVD-2026-64219","description":"The ManageWP Worker WordPress plugin before 4.9.37 does not bind the account being logged in to the signature which authorises the login, nor prevent an already used login link from being replayed, allowing attackers who obtain such a link to gain a session as any user on the site, including an administrator.","date":"2026-08-22"},{"id":"7b5e100a9a9b657656009f80bb5319fbada7d692","name":"ManageWP Worker < 4.9.37 - Authentication Bypass","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/worker\/managewp-worker-4937-authentication-bypass","description":"The ManageWP Worker plugin for WordPress is vulnerable to Authentication Bypass in all versions up to 4.9.37 (exclusive). This makes it possible for unauthenticated attackers to bypass authentication and log in as other users, including administrators.","date":"2026-05-13"}],"impact":{"cwe":[{"cwe":"CWE-287","name":"Improper Authentication","description":"When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"total","kev":false,"kev_date":null},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:H\/PR:N\/UI:N\/S:U\/C:H\/I:H\/A:H","score":"8.1","severity":"high","av":"network","ac":"high","pr":"none","ui":"none","s":"unchanged","c":"high","i":"high","a":"high","exploitable":null,"impact":null},"epss":"0.001"}}]},"updated":"1788417555"}