WP Staging is a WordPress plugin that provides staging and cloning functionality for site development and testing, serving developers who need isolated environments before deploying changes to production sites. The plugin's vulnerability footprint, while modest in volume, reflects the application-layer and access-control challenges inherent to a WordPress extension that handles sensitive site operations and database access. Defenders should monitor this plugin's updates closely given its administrative privilege scope, and live severity and exploitation counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Wp Staging over time
Signals from CVEs in this vendor scope (6 CVEs).
6 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-5551HIGH The WP STAGING Pro WordPress Backup Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 5.6.0. This is due to missing or i | Jun 14, 2024 | 8.8 | 25 | NO | NO |
CVE-2023-7204HIGH The WP STAGING WordPress Backup plugin before 3.2.0 allows access to cache files during the cloning process which provides | Jan 29, 2024 | 7.5 | 23 | NO | NO |
CVE-2023-6113HIGH The WP STAGING WordPress Backup Plugin before 3.1.3 and WP STAGING Pro WordPress Backup Plugin before 5.1.3 do not prevent visitors from leaking key information about ongoing backu | Jan 1, 2024 | 7.5 | 23 | NO | NO |
CVE-2024-4469HIGH The WP STAGING WordPress Backup Plugin WordPress plugin before 3.5.0 does not prevent users with the administrator role from pinging conducting SSRF attacks, which may be a proble | May 31, 2024 | 7.5 | 22 | NO | NO |
CVE-2022-2737MEDIUM The WP STAGING WordPress plugin before 2.9.18 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site S | Sep 16, 2022 | 4.8 | 19 | NO | NO |
CVE-2024-2309MEDIUM The WP STAGING WordPress Backup Plugin WordPress plugin before 3.4.0, wp-staging-pro WordPress plugin before 5.4.0 does not sanitise and escape some of its settings, which could a | Apr 17, 2024 | 4.8 | 17 | NO | NO |
Signals from CVEs in this vendor scope (6 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Wp Staging.
Media articles that mention a CVE ID that affects a product developed by Wp Staging — matched by CVE ID, not by vendor name.