Plugin Vulnerability Hub
Plugin 5 known issues Latest disclosed Sep 17, 2013

RokStories Vulnerabilities

Review known vulnerability records for the WordPress plugin RokStories (`wp_rokstories`), including severity, CVE references, affected versions, and patch status.

Known Records
5
High or Critical
3
Patch Coverage
100%
Last Updated
Jan 22, 2024
Coverage Snapshot

What this page helps you verify fast

This hub clusters every indexed record for RokStories so operators can confirm whether a disclosed issue maps to the installed slug, version range, and patch path.

Patch Visibility
5 records include a published patch path, leaving 0 with no listed safe release yet.
Severity Mix
1 critical and 2 high severity findings.
Recent CVEs
This page still provides patch and version coverage even when a CVE ID is not listed.
Reference Workflow
Jump from the hub into the full report when you need remediation notes, exploit context, CVSS vectors, or source references.
Triage First

Open the records most likely to drive action

These recent records surface the CVE strings, patch cues, and direct report links most operators need first.

Medium Patch path listed

RokStories <= 1.25 - Denial of Service

The WordPress RokStories plugin is vulnerable to Denial of Service via the 'src' parameter in the 'thumb.php' file in versions up to, and including, 1.25. This makes it possible for unauthen...

Published
Sep 17, 2013
Patch Status
1.26
High Patch path listed

RokStories <= 1.25 - Full Path Disclosure

The RokStories plugin for WordPress is vulnerable to Full Path Disclosure in versions up to, and including, 1.25 via the 'src' parameter in the 'thumb.php' and 'rokstories.php' files. This c...

Published
Sep 17, 2013
Patch Status
1.26
Medium Patch path listed

RokStories <= 1.25 - Cross-Site Scripting

The RokStories plugin for WordPress is vulnerable to Cross-Site Scripting via the 'src' parameter in the 'thumb.php' file in versions up to, and including, 1.25 due to insufficient input san...

Published
Sep 17, 2013
Patch Status
1.26
Known Vulnerabilities

Reports for RokStories

Sorted by latest disclosure date so newly published issues surface first.

Plugin Medium Patched: Yes
RokStories <= 1.25 - Denial of Service

The WordPress RokStories plugin is vulnerable to Denial of Service via the 'src' parameter in the 'thumb.php' file in versions up to, and including, 1.25. This makes it possible for unauthenticated attackers to slow the response time of the vulnerable service to an unusable speed...

Published
Sep 17, 2013
Patched Release
1.26
Affected Versions
Versions up to 1.25
Next Step
Update to 1.26 or newer if supported.
Plugin High Patched: Yes
RokStories <= 1.25 - Full Path Disclosure

The RokStories plugin for WordPress is vulnerable to Full Path Disclosure in versions up to, and including, 1.25 via the 'src' parameter in the 'thumb.php' and 'rokstories.php' files. This can allow unauthenticated attackers to extract otherwise restricted system file paths.

Published
Sep 17, 2013
Patched Release
1.26
Affected Versions
Versions up to 1.25
Next Step
Update to 1.26 or newer if supported.
Plugin Medium Patched: Yes
RokStories <= 1.25 - Cross-Site Scripting

The RokStories plugin for WordPress is vulnerable to Cross-Site Scripting via the 'src' parameter in the 'thumb.php' file in versions up to, and including, 1.25 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inj...

Published
Sep 17, 2013
Patched Release
1.26
Affected Versions
Versions up to 1.25
Next Step
Update to 1.26 or newer if supported.
Plugin Critical Patched: Yes
RokStories <= 1.25 - Arbitrary File Upload

The RokStories plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'src' parameter in the 'thumb.php' file in versions up to, and including, 1.25. This makes it possible for unauthenticated attackers to upload arbitrary files on...

Published
Sep 17, 2013
Patched Release
1.26
Affected Versions
Versions up to 1.25
Next Step
Update to 1.26 or newer if supported.
Plugin High Patched: Yes
RokStories <= 1.25 - Abuse of Functionality

The WordPress RokStories plugin is vulnerable to Abuse of Functionality via the 'src' parameter in the 'thumb.php' file in versions up to, and including, 1.25. This makes it possible for unauthenticated attackers to use implemented functions for unintended/malicious reasons.

Published
Sep 17, 2013
Patched Release
1.26
Affected Versions
Versions up to 1.25
Next Step
Update to 1.26 or newer if supported.