CVE-2025-12185
StaffList
Minimum safe version
3.2.7
Update to 3.2.7 or later to address 9 fixable vulnerabilities
WordPress StaffList plugin <= 3.2.7 - Broken Access Control vulnerability
WordPress StaffList plugin <= 3.2.7 - Sensitive Data Exposure vulnerability
CVE-2024-13749
StaffList < 3.1.6 - Arbitrary Staff Deletion via CSRF
StaffList < 3.1.6 - Reflected Cross-Site Scripting
StaffList < 3.1.7 - Reflected Cross-Site Scripting
StaffList <= 3.1.6 - Reflected Cross-Site Scripting
WordPress StaffList plugin <= 3.1.5 - Reflected Cross-Site Scripting (XSS) vulnerability
WordPress StaffList plugin <= 3.1.6 - Reflected Cross-Site Scripting (XSS) vulnerability
CVE-2022-1556
WordPress StaffList plugin <= 3.1.5 - Arbitrary Staff Deletion via Cross-Site Request Forgery (CSRF) vulnerability