Show filters
56 Total Results
Displaying 41-50 of 56
Sort by:
Attacker Value
Unknown
CVE-2023-41851
Disclosure Date: October 10, 2023 (last updated October 13, 2023)
Cross-Site Request Forgery (CSRF) vulnerability in Dotsquares WP Custom Post Template <= 1.0 versions.
0
Attacker Value
Unknown
CVE-2023-44238
Disclosure Date: October 09, 2023 (last updated October 13, 2023)
Cross-Site Request Forgery (CSRF) vulnerability in Joakim Ling Remove slug from custom post type plugin <= 1.0.3 versions.
0
Attacker Value
Unknown
CVE-2023-4792
Disclosure Date: September 07, 2023 (last updated November 09, 2023)
The Duplicate Post Page Menu & Custom Post Type plugin for WordPress is vulnerable to unauthorized page and post duplication due to a missing capability check on the duplicate_ppmc_post_as_draft function in versions up to, and including, 2.3.1. This makes it possible for authenticated attackers with subscriber access or higher to duplicate posts and pages.
0
Attacker Value
Unknown
CVE-2023-33329
Disclosure Date: July 18, 2023 (last updated October 08, 2023)
Auth. (admin+) Reflected Cross-Site Scripting (XSS) vulnerability in Hijiri Custom Post Type Generator plugin <= 2.4.2 versions.
0
Attacker Value
Unknown
CVE-2023-1016
Disclosure Date: June 09, 2023 (last updated October 08, 2023)
The Intuitive Custom Post Order plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 3.1.3, due to insufficient escaping on the user supplied 'objects' and 'tags' parameters and lack of sufficient preparation in the 'update_options' function as well as the 'refresh' function which runs queries on the same values. This allows authenticated attackers, with administrator permissions, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. Note that this attack may only be practical on configurations where it is possible to bypass addslashes due to the database using a nonstandard character set such as GBK.
0
Attacker Value
Unknown
CVE-2023-0542
Disclosure Date: May 08, 2023 (last updated October 08, 2023)
The Custom Post Type List Shortcode WordPress plugin through 1.4.4 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.
0
Attacker Value
Unknown
CVE-2023-1623
Disclosure Date: April 24, 2023 (last updated October 08, 2023)
The Custom Post Type UI WordPress plugin before 1.13.5 does not properly check for CSRF when sending the debug information to a user supplied email, which could allow attackers to make a logged in admin send such information to an arbitrary email address via a CSRF attack.
0
Attacker Value
Unknown
CVE-2023-0420
Disclosure Date: April 24, 2023 (last updated October 08, 2023)
The Custom Post Type and Taxonomy GUI Manager WordPress plugin through 1.1 does not have CSRF, and is lacking sanitising as well as escaping in some parameters, allowing attackers to make a logged in admin put Stored Cross-Site Scripting payloads via CSRF
0
Attacker Value
Unknown
CVE-2022-4386
Disclosure Date: February 21, 2023 (last updated October 08, 2023)
The Intuitive Custom Post Order WordPress plugin before 3.1.4 lacks CSRF protection in its update-menu-order ajax action, allowing an attacker to trick any user to change the menu order via a CSRF attack
0
Attacker Value
Unknown
CVE-2022-4385
Disclosure Date: February 21, 2023 (last updated October 08, 2023)
The Intuitive Custom Post Order WordPress plugin before 3.1.4 does not check for authorization in the update-menu-order ajax action, allowing any logged in user (with roles as low as Subscriber) to update the menu order
0