Social Auto Poster [accesspress-facebook-auto-post] <= 2.1.4 (unfixed + closed)
unknown
[en] Cross-Site Request Forgery (CSRF) vulnerability in AccessPress Themes Social Auto Poster plugin <= 2.1.4 versions.
- Affected:
- up to 2.1.4
- Fix:
- No patched version reported
- Disclosed:
- Nov 22, 2023
CVE-2023-26532 on NVD →
Social Auto Poster <= 2.1.4 - Cross-Site Request Forgery to Plugin Settings Reset
medium
The Social Auto Poster plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.1.4. This is due to missing or incorrect nonce validation on the 'restore_settings' function. This makes it possible for unauthenticated attackers to reset (and thus destroy) the current plugin se...
- CVSS:
- 4.3
- Affected:
- up to 2.1.4
- Fix:
- No patched version reported
- Disclosed:
- Feb 28, 2023
CVE-2023-26532 on NVD →
Social Auto Poster [accesspress-facebook-auto-post] < 2.1.4 (closed)
unknown
[en] Numerous Plugins and Themes from the AccessPress Themes (aka Access Keys) vendor are backdoored due to their website being compromised. Only plugins and themes downloaded via the vendor website are affected, and those hosted on wordpress.org are not. However, all of them were updated or removed to avoid any confus...
- Affected:
- up to 2.1.4
- Fixed in:
- 2.1.4
- Disclosed:
- Feb 21, 2022
CVE-2021-24867 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database