plugin

1003 Mortgage Application Vulnerabilities

5 known security issues reported for the 1003 Mortgage Application WordPress plugin. Most recent disclosed Jan 20, 2025.

1 high 4 medium

Running 1003 Mortgage Application on your site? Check whether your installed version is affected.

Scan your site free

1003 Mortgage Application <= 1.87 - Unauthenticated Full Path Disclosure

medium

The 1003 Mortgage Application plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 1.87. This is due the /inc/class/fnm/export.php file being publicly accessible with error logging enabled. This makes it possible for unauthenticated attackers to retrieve the full path of the...

CVSS:
5.3
Affected:
up to 1.87
Fix:
No patched version reported
Disclosed:
Jan 20, 2025

CVE-2024-13536 on NVD →

1003 Mortgage Application <= 1.87 - Missing Authorization

medium

The 1003 Mortgage Application plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 1.87. This makes it possible for unauthenticated attackers to perform an unauthorized action.

CVSS:
5.3
Affected:
up to 1.87
Fix:
No patched version reported
Disclosed:
Jan 7, 2025

CVE-2025-22592 on NVD →

1003 Mortgage Application <= 1.87 - Missing Authorization

medium

The 1003 Mortgage Application plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 1.87. This makes it possible for authenticated attackers, with Subscriber-level access and above, to perform an unauthorized action.

CVSS:
4.3
Affected:
up to 1.87
Fix:
No patched version reported
Disclosed:
Jan 7, 2025

CVE-2025-22591 on NVD →

1003 Mortgage Application <= 1.75 - Authenticated (Subscriber+) Arbitrary File Download

high

The 1003 Mortgage Application plugin for WordPress is vulnerable to arbitrary file download in versions up to, and including, 1.75 due to incorrect controls on the mortgate_application_download_file_callback() function. This makes it possible for authenticated attackers, with subscriber-level access or higher to downlo...

CVSS:
7.1
Affected:
up to 1.75
Fixed in:
1.80
Disclosed:
Feb 2, 2023

CVE-2022-45368 on NVD →

1003 Mortgage Application <= 1.75 - Unauthenticated CSV Injection

medium

The 1003 Mortgage Application plugin for WordPress is vulnerable to CSV Injection in versions up to, and including, 1.75. This allows unauthenticated attackers to embed untrusted input into exported CSV files, which can result in code execution when these files are downloaded and opened on a local system with a vulnera...

CVSS:
6.5
Affected:
up to 1.75
Fixed in:
1.80
Disclosed:
Feb 2, 2023

CVE-2022-45357 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database