plugin

Accessally Vulnerabilities

2 known security issues reported for the Accessally WordPress plugin. Most recent disclosed Mar 26, 2021.

1 critical 1 medium

Running Accessally on your site? Check whether your installed version is affected.

Scan your site free

AccessAlly <= 3.5.6 - Information Exposure

medium

In the AccessAlly WordPress plugin before 3.5.7, the file "resource/frontend/product/product-shortcode.php" responsible for the [accessally_order_form] shortcode is dumping serialize($_SERVER), which contains all environment variables. The leakage occurs on all public facing pages containing the [accessally_order_form]...

CVSS:
5.3
Affected:
up to 3.5.6
Fixed in:
3.5.7
Disclosed:
Mar 26, 2021

CVE-2021-24226 on NVD →

AccessAlly < 3.3.2 - Arbitrary Code Execution

critical

The AccessAlly plugin for WordPress is vulnerable to Arbitrary Code Execution in versions before 3.3.2 via the login_error function. This allows unauthenticated attackers to execute code on the server.

CVSS:
9.8
Affected:
up to 3.3.2
Fixed in:
3.3.2
Disclosed:
Jan 21, 2020

CVE-2020-36875 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database