Show filters
5 Total Results
Displaying 1-5 of 5
Sort by:
Attacker Value
Unknown
CVE-2023-46623
Disclosure Date: December 29, 2023 (last updated January 05, 2024)
Improper Control of Generation of Code ('Code Injection') vulnerability in TienCOP WP EXtra.This issue affects WP EXtra: from n/a through 6.2.
0
Attacker Value
Unknown
CVE-2023-46212
Disclosure Date: December 19, 2023 (last updated December 23, 2023)
Missing Authorization, Cross-Site Request Forgery (CSRF) vulnerability in TienCOP WP EXtra allows Accessing Functionality Not Properly Constrained by ACLs, Cross Site Request Forgery.This issue affects WP EXtra: from n/a through 6.2.
0
Attacker Value
Unknown
CVE-2023-47825
Disclosure Date: November 22, 2023 (last updated November 29, 2023)
Cross-Site Request Forgery (CSRF) vulnerability in TienCOP WP EXtra plugin <= 6.4 versions.
0
Attacker Value
Unknown
CVE-2023-5314
Disclosure Date: November 22, 2023 (last updated November 28, 2023)
The WP EXtra plugin for WordPress is vulnerable to unauthorized access to restricted functionality due to a missing capability check on the 'test-email' section of the register() function in versions up to, and including, 6.2. This makes it possible for authenticated attackers, with minimal permissions such as a subscriber, to send emails with arbitrary content to arbitrary locations from the affected site's mail server.
0
Attacker Value
Unknown
CVE-2023-5311
Disclosure Date: October 25, 2023 (last updated February 25, 2025)
The WP EXtra plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the register() function in versions up to, and including, 6.2. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to modify the contents of the .htaccess files located in a site's root directory or /wp-content and /wp-includes folders and achieve remote code execution.
0