plugin

Advanced Xml Reader Vulnerabilities

10 known security issues reported for the Advanced Xml Reader WordPress plugin. Most recent disclosed May 15, 2023.

1 critical 1 high

Running Advanced Xml Reader on your site? Check whether your installed version is affected.

Scan your site free

Advanced XML Reader [advanced-xml-reader] < 0.1.2

unknown

Update the plugin. An unknown person discovered and reported this Sensitive Data Exposure vulnerability in WordPress Advanced XML Reader Plugin. This vulnerability has been fixed in version 0.1.2.

Affected:
up to 0.1.2
Fixed in:
0.1.2
Disclosed:
May 15, 2023

Advanced XML Reader [advanced-xml-reader] < 0.3.5

unknown

Update the plugin. An unknown person discovered and reported this XML External Entity (XXE) vulnerability in WordPress Advanced XML Reader Plugin. A XXE attack could allow a malicious actor to inject arbitrary XML which could lead the website to leak sensitive information, cause a denial of service, and server side req...

Affected:
up to 0.3.5
Fixed in:
0.3.5
Disclosed:
May 15, 2023

Advanced XML Reader [advanced-xml-reader] < 0.3.5 (closed)

unknown

Because of this vulnerability, attackers can read system files or load the wp-config.php file. Update the plugin.

Affected:
up to 0.3.5
Fixed in:
0.3.5
Disclosed:
May 15, 2015

Advanced XML Reader [advanced-xml-reader] < 0.1.2 (closed)

unknown

This plugin is prone to a XML external entity data parsing arbitrary file disclosure vulnerability. It allows attackers to read system files. Update the plugin.

Affected:
up to 0.1.2
Fixed in:
0.1.2
Disclosed:
May 15, 2015

Advanced XML Reader <= 0.3.4 - External Entity Injection

critical

The Advanced XML Reader plugin for WordPress is vulnerable to XML External Entity Injection (XXE) in versions up to, and including, 0.3.4 via an unspecified parameter. This can allow unauthenticated attackers to extract sensitive data or achieve code execution in vulnerable configurations.

CVSS:
9.1
Affected:
up to 0.3.4
Fix:
No patched version reported
Disclosed:
May 2, 2013

Advanced XML Reader Plugin <= 0.3.4 - XML External Entity Injection

high

The Advanced XML Reader plugin for WordPress is vulnerable to XML External Entity Injection (XXE) in versions up to, and including, 0.3.4. This can allow authenticated attackers to extract sensitive data or achieve code execution in vulnerable configurations.

CVSS:
7.2
Affected:
up to 0.3.4
Fix:
No patched version reported
Disclosed:
May 2, 2013

Advanced XML Reader [advanced-xml-reader] <= 0.3.4 (unfixed)

unknown

The Advanced XML Reader plugin for WordPress is vulnerable to XML External Entity Injection (XXE) in versions up to, and including, 0.3.4. This can allow authenticated attackers to extract sensitive data or achieve code execution in vulnerable configurations.

Affected:
up to 0.3.4
Fix:
No patched version reported
Disclosed:
May 2, 2013

Advanced XML Reader [advanced-xml-reader] <= 0.3.4 (unfixed)

unknown

The Advanced XML Reader plugin for WordPress is vulnerable to XML External Entity Injection (XXE) in versions up to, and including, 0.3.4 via an unspecified parameter. This can allow unauthenticated attackers to extract sensitive data or achieve code execution in vulnerable configurations.

Affected:
up to 0.3.4
Fix:
No patched version reported
Disclosed:
May 2, 2013

Advanced XML Reader [advanced-xml-reader] <= 0.1.1 (unfixed + closed)

unknown

The advanced-xml-reader WordPress plugin was affected by a XML External Entity (XXE) Data Parsing Arbitrary File Disclosure security vulnerability.

Affected:
up to 0.1.1
Fix:
No patched version reported

Advanced XML Reader [advanced-xml-reader] <= 0.3.4 (unfixed + closed)

unknown

The advanced-xml-reader WordPress plugin was affected by a XML External Entity (XXE) Injection security vulnerability.

Affected:
up to 0.3.4
Fix:
No patched version reported

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database