Show filters
6 Total Results
Displaying 1-6 of 6
Sort by:
Attacker Value
Unknown

CVE-2024-9626

Disclosure Date: October 26, 2024 (last updated October 26, 2024)
The Editorial Assistant by Sovrn plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'ajax_zemanta_set_featured_image' function in versions up to, and including, 1.3.3. This makes it possible for authenticated attackers, with subscriber-level access and above, to upload attachment files (such as jpg, png, txt, zip), and set the post featured image.
0
Attacker Value
Unknown

CVE-2013-3257

Disclosure Date: June 02, 2014 (last updated October 05, 2023)
Cross-site request forgery (CSRF) vulnerability in the Related Posts plugin before 2.7.2 for WordPress allows remote attackers to hijack the authentication of users for requests that modify settings via unspecified vectors.
0
Attacker Value
Unknown

CVE-2013-3476

Disclosure Date: June 02, 2014 (last updated October 05, 2023)
Cross-site request forgery (CSRF) vulnerability in the WordPress Related Posts plugin before 2.6.2 for WordPress allows remote attackers to hijack the authentication of users for requests that change settings via unspecified vectors.
0
Attacker Value
Unknown

CVE-2013-3477

Disclosure Date: May 27, 2014 (last updated October 05, 2023)
Cross-site request forgery (CSRF) vulnerability in the Related Posts by Zemanta plugin before 1.3.2 for WordPress allows remote attackers to hijack the authentication of unspecified users for requests that change settings via unknown vectors.
0
Attacker Value
Unknown

CVE-2014-3843

Disclosure Date: May 22, 2014 (last updated October 05, 2023)
Cross-site request forgery (CSRF) vulnerability in the Search Everything plugin before 8.1.1 for WordPress allows remote attackers to hijack the authentication of unspecified victims via unknown vectors.
0
Attacker Value
Unknown

CVE-2014-2316

Disclosure Date: March 09, 2014 (last updated October 05, 2023)
SQL injection vulnerability in se_search_default in the Search Everything plugin before 7.0.3 for WordPress allows remote attackers to execute arbitrary SQL commands via the s parameter to index.php. NOTE: some of these details are obtained from third party information.
0