Community by PeepSo – Download from PeepSo.com

Community by PeepSo – Download from PeepSo.com

peepso-core
WordPress Plugin DirectoryWordPress Plugin Directory
Unavailable
This project is no longer available (or publicly accessible) from WordPress Plugin Directory
Releases10
Frequency3 weeks 1 day
Last Release
Downloads469K

We decided to stop using WordPress.org Plugins Repository. To get PeepSo plugins, please go to: PeepSo.com – you can download free PeepSo plugin there.

More Information

More plugins are currently being developed to extend PeepSo’s functionality. To get your desired plugin, see our PeepSo Pricing Page.

CVE History

CVEPublishedCVSS v3CVSS v2
5.3 MEDIUM

The Community by PeepSo – Social Network, Membership, Registration, User Profiles plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 6.4.6.0. This is due to the plugin displaying errors and allowing direct access to the sse.php file. This makes it possible for unauthenticated attackers to retrieve the full path of the web application, which can be used to aid other attacks. The information displayed is not useful on its own, and requires another vulnerability to be present for damage to an affected website.

4.4 MEDIUM

The Community by PeepSo – Social Network, Membership, Registration, User Profiles plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘content’ parameter in all versions up to, and including, 6.4.5.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level access, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.

4.4 MEDIUM

The Community by PeepSo – Social Network, Membership, Registration, User Profiles plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 6.4.5.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level access, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.