wp-greet

wp-greet has one disclosed vulnerability in the WordSec catalog, all reported in 2025; it is fixed as of September 2026. Their average CVSS score is 6.1, and the most serious one scores 6.1 out of 10.

The most common weakness is Cross-Site Request Forgery (CSRF), behind 1 of the records (100%).

The one issue recorded for wp-greet has a vendor fix available, so running the current release closes it.

All of these findings were reported by SOPROBRO. wp-greet is installed on roughly 50 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 6.9.7.

Strategic Overview

Avg CVSSMedium
6.1/ 10
Patch Coverage100%
Open

0

Fixed

1

Get automatic notifications for all wp-greet vulnerabilities before they are exploited.

Highest severity on recordCVSS 6.1CVE-2024-13444

wp-greet <= 6.2 - Cross-Site Request Forgery to Stored Cross-Site Scripting

Read the full analysis

Vulnerability Records

1 records
wp-greet banner
Latestv6.3

wp-greet

tuxlog

Author

tuxlog

4.9(10)
98/100
Last Updated
2025-12-06 (9mo ago)
Active Installs
50+
Downloads
35,624
Requires WP
4.1+
Requires PHP
0+
Tested up to
WP 6.9.7
Created
2008-04-06 (19y ago)

wp-greet is a plugin for the famous WordPress blogging system, giving your users the ability to send greeting cards from your blog. Features: uses WordPress native gallery NextCellentGallery or NextGenGallery for maintainig the greeting card picture storing statistics about the sent greeting cards adding your own css control who can send cards add default subject, header and footer to the greeting cards various settings for sending the mails (SMTP, SSL, PHPMail) supports Antispam Plugins CaptCha! and Math-Comment-Spam-Protection-Plugin sign your greeting cards with your own stamp backgroundmusic for your cards supports individual terms of usage supports confirmation mail processing supports fetching the card online or sent it by mail can send cards in the future WPML certified Using HOWLER.js (https://github.com/goldfire/howler.js) Copyright (c) 2013-2018 James Simpson and GoldFire Studios, Inc. Released under the MIT License. requirements WordPress >= 4.1.x Optional: NextCellentGallery, NextGenGallery >= v1.90 update from prior v1.1 IMPORTANT: Please be sure to remove all files belonging to versions prior to v1.1 before uploading v1.1 Please be sure to remove the patched version of nggfunctions.php which was necessary to integrate wp-greet with NextGenGallery prior to version 1.1<h3>update to v1.7 and higher</h3>IMPORTANT: Please be sure to deactivate and activate the plugin one time because the database updates will only be executed during plugin activation<h3>usage from v1.1 on</h3>1. Create a page or posting containing the tag [wp-greet]. 1. Remember the permalink of this page/post 1. Enter the page/post number at the wp-greet admin dialog into the field Form-Post/Page and switch to your favourite gallery plugin 1. Create a page with your favourite gallery on it using the following syntax, e.g. for ngg: [gallery=1] 1. thats it, just klick on a picture on the gallery page and send it For more details see the online documentation of wp-greet. http://www.tuxlog.de/wordpress/2008/wp-greet-documentation-english/ translations wp-greet comes with english and german translations. if you would like to add a new translation, just take the file wp-greet.pot (in the wp-greet main directory) copy it to .po and edit it to add your translations (e.g. with poedit). Meanwhile a swedish, french, italians and vietnames translation was kindly build by other users. See Changelog for credits.

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C