WeblizarCVEs & Vulnerabilities

11 CVEs affecting Weblizar products, tracked from the National Vulnerability Database, with CVSS/EPSS scores and exploitation status.

Most Affected Products

pinterest-feeds 4admin custom login 2school management 2responsive coming soon \& maintenance mode 1school management - education \& learning management 1social likebox \& feed 1
CVE-2022-1609KEVCRITICALin the wild

The School Management WordPress plugin before 9.9.7 contains an obfuscated backdoor injected in it's license checking code that registers a REST API handler, allowing an unauthenticated attacker to execute arbitrary PHP code on the site.

11 Apr 2026
9.8
CVSS
CVE-2024-33911HIGH

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Weblizar School Management Pro.This issue affects School Management Pro: from n/a through 10.3.4.

2 May 2024
7.2
CVSS
CVE-2022-47430CRITICAL

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Weblizar The School Management – Education & Learning Management allows SQL Injection.This issue affects The School Management – Education & Learning Management: from n/a through 4.1.

6 Nov 2023
9.8
CVSS
CVE-2022-46849CRITICAL

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Weblizar Coming Soon Page – Responsive Coming Soon & Maintenance Mode allows SQL Injection.This issue affects Coming Soon Page – Responsive Coming Soon & Maintenance Mode: from n/a through 1.5.9.

6 Nov 2023
9.8
CVSS
CVE-2017-20098MEDIUM

A vulnerability was found in Admin Custom Login Plugin 2.4.5.2. It has been classified as problematic. Affected is an unknown function. The manipulation leads to basic cross site scripting (Persistent). It is possible to launch the attack remotely.

27 Jun 2022
4.8
CVSS
CVE-2021-34628HIGH

The Admin Custom Login WordPress plugin is vulnerable to Cross-Site Request Forgery due to the loginbgSave action found in the ~/includes/Login-form-setting/Login-form-background.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 3.2.7.

3 Aug 2021
8.8
CVSS
CVE-2019-15781HIGH

The facebook-by-weblizar plugin before 2.8.5 for WordPress has CSRF.

29 Aug 2019
8.8
CVSS
CVE-2018-5656HIGH

An issue was discovered in the weblizar-pinterest-feeds plugin 1.1.1 for WordPress. CSRF exists via wp-admin/admin-ajax.php.

13 Jan 2018
8.8
CVSS
CVE-2018-5655MEDIUM

An issue was discovered in the weblizar-pinterest-feeds plugin 1.1.1 for WordPress. XSS exists via the wp-admin/admin-ajax.php security parameter.

13 Jan 2018
6.1
CVSS
CVE-2018-5654MEDIUM

An issue was discovered in the weblizar-pinterest-feeds plugin 1.1.1 for WordPress. XSS exists via the wp-admin/admin-ajax.php PFFREE_Access_Token parameter.

13 Jan 2018
6.1
CVSS
CVE-2018-5653MEDIUM

An issue was discovered in the weblizar-pinterest-feeds plugin 1.1.1 for WordPress. XSS exists via the wp-admin/admin-ajax.php weblizar_pffree_settings_save_get-users parameter.

13 Jan 2018
6.1
CVSS
← PrevPage 1 / 1Next →