Vulnerabilities / WebinarPress
WebinarPress vulnerabilities
Advisories WPSec published for WebinarPress – Webinar System for WordPress. Other sources may list more. Its attack surface: WebinarPress on WPSec AttackSurface.
| Published | ID | Vulnerability | Severity | Fixed in |
|---|---|---|---|---|
| 2026-10-07 | WPSEC-2026-0547 | WebinarPress <= 1.33.30 - Unauthenticated Reflected Cross-Site Scripting via 'content' Parameter | Medium 6.1 | 1.33.31 |
| 2026-10-07 | WPSEC-2026-0546 | WebinarPress <= 1.33.30 - Unauthenticated Missing Authorization to Multiple AJAX Actions | Medium 6.5 | 1.33.31 |
| 2026-10-07 | WPSEC-2026-0545 | WebinarPress <= 1.33.30 - Authenticated (Subscriber+) Missing Authorization to Multiple Administrative Actions | Medium 5.4 | 1.33.31 |
License: CC BY 4.0