Cross-Site Scripting
10 records90.9%First: 2023. Latest: 2026.
Plugin security history
The Wordfence Intelligence dataset currently contains 11 vulnerability records associated with VK All in One Expansion Unit, published between 2023 and 2026.
Dataset last synchronized: 2026-08-03 00:31:25 UTC
At a glance
Use this history
A history record does not establish whether the version installed on your website is affected. Enter the exact version in the checker, or add this software to a private Critical/High alert watchlist.
| Year | Records | Relative volume |
|---|---|---|
| 2023 | 4 | |
| 2024 | 3 | |
| 2025 | 2 | |
| 2026 | 2 |
| Severity | Records | Share |
|---|---|---|
| Medium | 11 | 100% |
First: 2023. Latest: 2026.
First: 2024. Latest: 2024.
Patch status reflects the latest successfully synchronized source dataset and must be checked against the installed version.
9.113.49.112.49.112.29.99.2.09.96.0.09.97.0.09.88.2.09.87.1.09.86.0.0Ranges are deduplicated by source range record and shown with the associated disclosure and known patched versions.
| Affected range | Vulnerability | Published | Patched version | Severity |
|---|---|---|---|---|
*-9.113.3 | VK All in One Expansion Unit <= 9.113.3 - Authenticated (Contributor+) Stored Cross-Site Scripting | March 23, 2026 | 9.113.4 | Medium |
*-9.112.3 | VK All in One Expansion Unit <= 9.112.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via SNS Title | February 17, 2026 | 9.112.4 | Medium |
*-9.112.1 | VK All in One Expansion Unit <= 9.112.1 - Authenticated (Contributor+) Stored Cross-Site Scripting | November 17, 2025 | 9.112.2 | Medium |
*-9.112.1 | VK All in One Expansion Unit <= 9.112.1 - Authenticated (Contributor+) Stored Cross-Site Scripting | November 17, 2025 | 9.112.2 | Medium |
*-9.99.1.0 | VK All in One Expansion Unit <= 9.99.1.0 - Authenticated (Contributor+) Stored Cross-Site Scripting | July 10, 2024 | 9.99.2.0 | Medium |
*-9.95.0.1 | VK All in One Expansion Unit <= 9.95.0.1 - Information Exposure | March 26, 2024 | 9.96.0.0 | Medium |
*-9.96.0.1 | VK All in One Expansion Unit <= 9.96.0.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via className | March 25, 2024 | 9.97.0.0 | Medium |
*-9.88.1.0 | VK All in One Expansion Unit <= 9.88.1.0 - Stored (Contributor+) Cross-Site Scripting in Profile Setting | May 9, 2023 | 9.88.2.0 | Medium |
*-9.88.1.0 | VK All in One Expansion Unit <= 9.88.1.0 - Stored (Contributor+) Cross-Site Scripting in CTA Post | May 9, 2023 | 9.88.2.0 | Medium |
*-9.87.0.1 | VK All in One Expansion Unit <= 9.87.0.1 - Reflected Cross-Site Scripting via REQUEST_URI | February 22, 2023 | 9.87.1.0 | Medium |
*-9.85.0.1 | VK All in One Expansion Unit <= 9.85.0.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode | February 3, 2023 | 9.86.0.0 | Medium |
Selected source records
Published: March 23, 2026
Published: February 17, 2026
Published: November 17, 2025
Published: November 17, 2025
Published: July 10, 2024
Published: March 26, 2024
Published: March 25, 2024
Published: May 9, 2023
Published: March 26, 2024
Published: March 25, 2024
Published: May 9, 2023
Published: February 17, 2026
Published: May 9, 2023
Published: November 17, 2025
Published: November 17, 2025
Published: July 10, 2024
Running an affected version does not prove that a website was compromised. Suspicious redirects, unknown administrators, injected content, unexpected files or recurring malware may require a manual investigation.
Vulnerability data: Wordfence Intelligence. Analysis and practical guidance: 3Zero Digital.
This page aggregates active Production Feed records. Counts are not software-quality rankings, and an affected version does not prove exploitation or infection. Read the full methodology.