Wpmilitary's vulnerability footprint concentrates in its WP Radio product, a WordPress-oriented application where the recurring signal centers on web application access and input-handling weaknesses: missing authorization controls, cross-site request forgery, and cross-site scripting. These flaw classes are characteristic of plugin and web-application development and reflect the attack surface presented by unauthenticated and authenticated user interactions in WordPress ecosystems. Current severity, exploitation status, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Wpmilitary over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-46150HIGH Cross-Site Request Forgery (CSRF) vulnerability in WP Military WP Radio plugin <= 3.1.9 versions. | Oct 25, 2023 | 8.8 | 21 | NO | NO |
CVE-2024-1042MEDIUM The WP Radio – Worldwide Online Radio Stations Directory for WordPress plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on | Apr 10, 2024 | 5.4 | 16 | NO | NO |
CVE-2024-1041MEDIUM The WP Radio – Worldwide Online Radio Stations Directory for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's settings in all versions u | Apr 10, 2024 | 5.4 | 15 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Wpmilitary.
Media articles that mention a CVE ID that affects a product developed by Wpmilitary — matched by CVE ID, not by vendor name.