Show filters
4 Total Results
Displaying 1-4 of 4
Sort by:
Attacker Value
Unknown
CVE-2022-2446
Disclosure Date: September 13, 2024 (last updated September 27, 2024)
The WP Editor plugin for WordPress is vulnerable to deserialization of untrusted input via the 'current_theme_root' parameter in versions up to, and including 1.2.9. This makes it possible for authenticated attackers with administrative privileges to call files using a PHAR wrapper that will deserialize and call arbitrary PHP Objects that can be used to perform a variety of malicious actions granted a POP chain is also present. It also requires that the attacker is successful in uploading a file with the serialized payload.
0
Attacker Value
Unknown
CVE-2021-24151
Disclosure Date: January 16, 2024 (last updated January 24, 2024)
The WP Editor WordPress plugin before 1.2.7 did not sanitise or validate its setting fields leading to an authenticated (admin+) blind SQL injection issue via an arbitrary parameter when making a request to save the settings.
0
Attacker Value
Unknown
CVE-2016-10886
Disclosure Date: August 14, 2019 (last updated January 24, 2024)
The wp-editor plugin before 1.2.6 for WordPress has incorrect permissions.
0
Attacker Value
Unknown
CVE-2016-10885
Disclosure Date: August 14, 2019 (last updated January 24, 2024)
The wp-editor plugin before 1.2.6 for WordPress has CSRF.
0