Rencontre <= 3.13.7 - Authenticated (Administrator+) Stored Cross-Site Scripting
Rencontre – Dating Site
Minimum safe version
3.13.8
Update to 3.13.8 or later to address 16 fixable vulnerabilities
CVE-2025-67534
WordPress Rencontre – Dating Site Plugin <= 3.11.1 is vulnerable to PHP Object Injection
WordPress Rencontre – Dating Site Plugin <= 3.10.1 is vulnerable to Arbitrary File Upload
WordPress Rencontre – Dating Site Plugin <= 3.10.1 is vulnerable to Privilege Escalation
Rencontre < 3.2.2 - Authenticated Stored XSS via facebook parameter & SQL Injection
Rencontre < 3.2 - Authenticated Stored XSS via textmail & textanniv Parameters
Rencontre <= 3.2.2 - Multiple CSRF
Rencontre – Dating Site <= 3.2.1 - Authenticated (Admin+) SQL Injection
Rencontre – Dating Site <= 3.1.3 - Authenticated (Admin+) Stored Cross-Site Scripting
Rencontre – Dating Site <= 3.2.1 - Authenticated (Admin+) Stored Cross-Site Scripting
Rencontre – Dating Site <= 3.2.2 - Cross-Site Request Forgery
WordPress Rencontre – Dating Site plugin <= 3.1.2 - SQL Injection (SQLi) and Cross-Site Scripting (XSS) vulnerabilities
WordPress Rencontre – Dating Site plugin <= 3.2.2 - Multiple Cross-Site Request Forgery (CSRF) vulnerabilities
CVE-2019-13414
CVE-2019-13413