N/A
2026-02-17< 6.3.0
WP Plugin Info Card <= 6.2.0 - Cross-Site Request Forgery to Arbitrary Custom Plugin Entry Creation
Minimum safe version
6.3.0
Update to 6.3.0 or later to address 5 fixable vulnerabilities
WP Plugin Info Card <= 6.2.0 - Cross-Site Request Forgery to Arbitrary Custom Plugin Entry Creation
WP Plugin Info Card <= 5.3.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via containerid Parameter
CVE-2025-31835
Plugin Info Card <= 2.3.6 - Authenticated XSS
WP Plugin Info Card < 2.3.7 - Cross-Site Scripting