Plugin Vulnerability Hub
Plugin 1 known issue Latest disclosed Feb 11, 2014

Acunetix WP Security Vulnerabilities

Review known vulnerability records for the WordPress plugin Acunetix WP Security (`wp-security-scan`), including severity, CVE references, affected versions, and patch status.

Known Records
1
High or Critical
1
Linked CVEs
0
Last Updated
Jan 22, 2024
Coverage Snapshot

What this page helps you verify fast

This hub clusters every indexed record for Acunetix WP Security so operators can quickly confirm whether a disclosed issue maps to the installed slug and version range.

Patch Visibility
1 record include a published patch path.
Severity Mix
0 critical and 1 high severity finding.
Reference Workflow
Jump from the hub into the full report when you need remediation notes, CVSS vector details, or source references.
Known Vulnerabilities

Reports for Acunetix WP Security

Sorted by latest disclosure date so newly published issues surface first.

Plugin High Patched: Yes
Acunetix WP Security <= 4.0.4 - Cross-Site Request Forgery

The Acunetix WP Security plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 4.0.4. This is due to missing or incorrect nonce validation in the ~/box-database-backup.php file. This makes it possible for unauthenticated attackers to t...

Published
Feb 11, 2014
Patched Release
4.0.5
Affected Versions
Versions before 4.0.5
Next Step
Update to 4.0.5 or newer if supported.