CVE-2025-49318
WPtouch – Make your WordPress Website Mobile-Friendly
Minimum safe version
4.3.61
Update to 4.3.61 or later to address 23 fixable vulnerabilities
WPtouch 3.x - Insecure Nonce Generation
WPtouch 1.9.8 - include/submit.php Multiple Parameter SQL Injection
WPtouch 1.9.8 - ajax/file_upload.php Crafted Content-Type File Upload Remote Code Execution
WPtouch 1.9.27 - 'wptouch_redirect' Parameter URI Redirection
WPtouch <= 3.6.6 - Unvalidated Open Redirect
WPtouch Mobile Plugin <= 3.7.5.3 - Cross-Site Scripting (XSS)
WPtouch < 4.3.44 - Reflected Cross-Site Scripting
WPtouch <= 3.4.2 - Arbitrary File Upload
WPtouch < 1.9.30 - Open Redirect
WPTouch < 3.7 - Open Redirect
WPtouch <= 3.7.5.3 - Cross-Site Scripting
CVE-2022-3416
CVE-2022-3417
WPtouch <= 4.3.42 - Reflected Cross-Site Scripting
WordPress WPtouch plugin <= 4.3.42 - Reflected Cross-Site Scripting (XSS) vulnerability
WordPress WPtouch Plugin <= 3.6.6 - Open Redirection
WordPress WPtouch Plugin <= 1.9.8 - SQL Injection
WordPress WPtouch Plugin <= 1.9.8 - Remote Code Executio
WordPress WPtouch Plugin <= 3.x - Insecure Nonce Generation
WordPress WPtouch Plugin 1.9.27 - URL redirection
CVE-2010-4779
CVE-2011-4803