Show filters
51 Total Results
Displaying 31-40 of 51
Sort by:
Attacker Value
Unknown

CVE-2022-4496

Disclosure Date: January 30, 2023 (last updated October 08, 2023)
The SAML SSO Standard WordPress plugin version 16.0.0 before 16.0.8, SAML SSO Premium WordPress plugin version 12.0.0 before 12.1.0 and SAML SSO Premium Multisite WordPress plugin version 20.0.0 before 20.0.7 does not validate that the redirect parameter to its SSO login endpoint points to an internal site URL, making it vulnerable to an Open Redirect issue when the user is already logged in.
Attacker Value
Unknown

CVE-2023-23749

Disclosure Date: January 17, 2023 (last updated October 08, 2023)
The 'LDAP Integration with Active Directory and OpenLDAP - NTLM & Kerberos Login' extension is vulnerable to LDAP Injection since is not properly sanitizing the 'username' POST parameter. An attacker can manipulate this paramter to dump arbitrary contents form the LDAP Database.
Attacker Value
Unknown

CVE-2022-4200

Disclosure Date: January 02, 2023 (last updated October 08, 2023)
The Login with Cognito WordPress plugin through 1.4.8 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).
Attacker Value
Unknown

CVE-2022-45073

Disclosure Date: November 09, 2022 (last updated December 22, 2024)
Cross-Site Request Forgery (CSRF) vulnerability in REST API Authentication plugin <= 2.4.0 on WordPress.
Attacker Value
Unknown

CVE-2022-42461

Disclosure Date: October 31, 2022 (last updated December 22, 2024)
Broken Access Control vulnerability in miniOrange's Google Authenticator plugin <= 5.6.1 on WordPress.
Attacker Value
Unknown

CVE-2022-3082

Disclosure Date: October 17, 2022 (last updated October 08, 2023)
The miniOrange Discord Integration WordPress plugin before 2.1.6 does not have authorisation and CSRF in some of its AJAX actions, allowing any logged in users, such as subscriber to call them, and disable the app for example
Attacker Value
Unknown

CVE-2022-34149

Disclosure Date: August 02, 2022 (last updated September 17, 2024)
Authentication Bypass vulnerability in miniOrange WP OAuth Server plugin <= 3.0.4 at WordPress.
Attacker Value
Unknown

CVE-2022-34858

Disclosure Date: August 02, 2022 (last updated September 17, 2024)
Authentication Bypass vulnerability in miniOrange OAuth 2.0 client for SSO plugin <= 1.11.3 at WordPress.
Attacker Value
Unknown

CVE-2022-2133

Disclosure Date: July 17, 2022 (last updated October 07, 2023)
The OAuth Single Sign On WordPress plugin before 6.22.6 doesn't validate that OAuth access token requests are legitimate, which allows attackers to log onto the site with the only knowledge of a user's email address.
Attacker Value
Unknown

CVE-2022-1995

Disclosure Date: June 27, 2022 (last updated October 07, 2023)
The Malware Scanner WordPress plugin before 4.5.2 does not sanitise and escape some of its settings, leading to malicious users with administrator privileges to store malicious Javascript code leading to Cross-Site Scripting attacks when unfiltered_html is disallowed (for example in multisite setup)