Absolute Privacy <= 2.1 - Cross-Site Request Forgery to User Email/Password Change
high
The Absolute Privacy plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.1. This is due to missing nonce validation on the 'abpr_profileShortcode' function. This makes it possible for unauthenticated attackers to change user email and password via a forged request grante...
- CVSS:
- 8.8
- Affected:
- up to 2.1
- Fix:
- No patched version reported
- Disclosed:
- Aug 9, 2023
CVE-2023-4276 on NVD →
Absolute Privacy <= 2.0.5 - Authentication Bypass
critical
The Absolute Privacy plugin for WordPress is vulnerable to Authentication Bypass in versions up to, and including, 2.0.5. This is due to improper handling of password verification. This makes it possible for unauthenticated attackers to log in with any legitimate username, including administrator accounts, and any pass...
- CVSS:
- 9.8
- Affected:
- up to 2.0.5
- Fixed in:
- 2.0.6
- Disclosed:
- Dec 15, 2011
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database