3DPrint [3dprint] < 3.5.6.9
unknown
[en] The 3dprint WordPress plugin before 3.5.6.9 does not protect against CSRF attacks in the modified version of Tiny File Manager included with the plugin, allowing an attacker to craft a malicious request that will delete any number of files or directories on the target server by tricking a logged in admin into subm...
- Affected:
- up to 3.5.6.9
- Fixed in:
- 3.5.6.9
- Disclosed:
- Jan 16, 2024
CVE-2022-3899 on NVD →
3DPrint [3dprint] < 3.5.6.9
unknown
[en] The 3DPrint WordPress plugin before 3.5.6.9 does not protect against CSRF attacks in the modified version of Tiny File Manager included with the plugin, allowing an attacker to craft a malicious request that will create an archive of any files or directories on the target server by tricking a logged in admin into...
- Affected:
- up to 3.5.6.9
- Fixed in:
- 3.5.6.9
- Disclosed:
- Jul 17, 2023
CVE-2022-4023 on NVD →
3DPrint < 3.5.6.9 - Cross-Site Request Forgery to Arbitrary File Deletion
high
The 3DPrint plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and excluding, 3.5.6.9. This is due to missing or incorrect nonce validation on one of its functions. This makes it possible for unauthenticated attackers to delete arbitrary files and directories, via forged request granted...
- CVSS:
- 8.8
- Affected:
- up to 3.5.4.8
- Fixed in:
- 3.5.6.9
- Disclosed:
- Nov 8, 2022
CVE-2022-3899 on NVD →
3DPrint <= 3.5.6.8 - Cross-Site Request Forgery to Arbitrary File Download
high
The 3DPrint plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.5.6.9. This is due to missing or incorrect nonce validation in the tinyfilemanager.php file. This makes it possible for unauthenticated attackers to create a backup of any file or directory on the site via a...
- CVSS:
- 8.1
- Affected:
- up to 3.5.6.9
- Fix:
- No patched version reported
- Disclosed:
- Sep 8, 2022
CVE-2022-4023 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database