plugin

3Dprint Vulnerabilities

4 known security issues reported for the 3Dprint WordPress plugin. Most recent disclosed Jan 16, 2024.

2 high

Running 3Dprint on your site? Check whether your installed version is affected.

Scan your site free

3DPrint [3dprint] < 3.5.6.9

unknown

[en] The 3dprint WordPress plugin before 3.5.6.9 does not protect against CSRF attacks in the modified version of Tiny File Manager included with the plugin, allowing an attacker to craft a malicious request that will delete any number of files or directories on the target server by tricking a logged in admin into subm...

Affected:
up to 3.5.6.9
Fixed in:
3.5.6.9
Disclosed:
Jan 16, 2024

CVE-2022-3899 on NVD →

3DPrint [3dprint] < 3.5.6.9

unknown

[en] The 3DPrint WordPress plugin before 3.5.6.9 does not protect against CSRF attacks in the modified version of Tiny File Manager included with the plugin, allowing an attacker to craft a malicious request that will create an archive of any files or directories on the target server by tricking a logged in admin into...

Affected:
up to 3.5.6.9
Fixed in:
3.5.6.9
Disclosed:
Jul 17, 2023

CVE-2022-4023 on NVD →

3DPrint < 3.5.6.9 - Cross-Site Request Forgery to Arbitrary File Deletion

high

The 3DPrint plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and excluding, 3.5.6.9. This is due to missing or incorrect nonce validation on one of its functions. This makes it possible for unauthenticated attackers to delete arbitrary files and directories, via forged request granted...

CVSS:
8.8
Affected:
up to 3.5.4.8
Fixed in:
3.5.6.9
Disclosed:
Nov 8, 2022

CVE-2022-3899 on NVD →

3DPrint <= 3.5.6.8 - Cross-Site Request Forgery to Arbitrary File Download

high

The 3DPrint plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.5.6.9. This is due to missing or incorrect nonce validation in the tinyfilemanager.php file. This makes it possible for unauthenticated attackers to create a backup of any file or directory on the site via a...

CVSS:
8.1
Affected:
up to 3.5.6.9
Fix:
No patched version reported
Disclosed:
Sep 8, 2022

CVE-2022-4023 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database