plugin

Ag Custom Admin Vulnerabilities

12 known security issues reported for the Ag Custom Admin WordPress plugin. Most recent disclosed Apr 29, 2024.

5 medium

Running Ag Custom Admin on your site? Check whether your installed version is affected.

Scan your site free

AGCA &#8211; Custom Dashboard &amp; Login Page [ag-custom-admin] < 7.2.4

unknown

[en] Server-Side Request Forgery (SSRF) vulnerability in Cusmin Absolutely Glamorous Custom Admin.This issue affects Absolutely Glamorous Custom Admin: from n/a through 7.2.2.

Affected:
up to 7.2.4
Fixed in:
7.2.4
Disclosed:
Apr 29, 2024

CVE-2024-33627 on NVD →

AGCA &#8211; Custom Dashboard &amp; Login Page [ag-custom-admin] < 7.2.2

unknown

[en] The AGCA WordPress plugin before 7.2.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

Affected:
up to 7.2.2
Fixed in:
7.2.2
Disclosed:
Apr 25, 2024

CVE-2024-2907 on NVD →

Absolutely Glamorous Custom Admin <= 7.2.3 - Authenticated (Admin+) Server-Side Request Forgery

medium

The AGCA – Custom Dashboard & Login Page plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 7.2.3. This makes it possible for authenticated attackers, with administrator-level access and above, to make web requests to arbitrary locations originating from the web appl...

CVSS:
5.5
Affected:
up to 7.2.3
Fixed in:
7.2.4
Disclosed:
Apr 24, 2024

CVE-2024-33627 on NVD →

AGCA – Custom Dashboard & Login Page <= 7.2.1 - Authenticated (Admin+) Stored Cross-Site Scripting

medium

The AGCA – Custom Dashboard & Login Page plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 7.2.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions a...

CVSS:
4.4
Affected:
up to 7.2.1
Fixed in:
7.2.2
Disclosed:
Apr 4, 2024

CVE-2024-2907 on NVD →

AGCA &#8211; Custom Dashboard &amp; Login Page [ag-custom-admin] < 7.0

unknown

[en] The Custom Dashboard & Login Page WordPress plugin before 7.0 does not sanitise some of its settings, allowing high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.

Affected:
up to 7.0
Fixed in:
7.0
Disclosed:
Feb 1, 2022

CVE-2021-24944 on NVD →

Custom Dashboard & Login Page < 6.9.5 - Admin+ Stored Cross-Site Scripting

medium

The Custom Dashboard & Login Page WordPress plugin before 7.0 does not sanitise some of its settings, allowing high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.

CVSS:
4.8
Affected:
up to 6.9.5
Fixed in:
7.0
Disclosed:
Dec 30, 2021

CVE-2021-24944 on NVD →

Absolutely Glamorous Custom Admin <= 6.8 - Authenticated Stored Cross-Site Scripting

medium

Authenticated Stored Cross-Site Scripting (XSS) vulnerability in WordPress Absolutely Glamorous Custom Admin plugin (versions <= 6.8). Stored XSS possible via unsanitized input fields of the plugin settings, some of the payloads could make the frontend and the backend inaccessible.

CVSS:
6.6
Affected:
up to 6.8
Fixed in:
6.9
Disclosed:
Sep 23, 2021

CVE-2021-36823 on NVD →

AGCA &#8211; Custom Dashboard &amp; Login Page [ag-custom-admin] < 6.9.2

unknown

[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Cusmin AGCA - Absolutely Glamorous Custom Admin (WordPress plugin) allows Stored XSS.This issue affects AGCA - Absolutely Glamorous Custom Admin (WordPress plugin): from n/a through 6.8.

Affected:
up to 6.9.2
Fixed in:
6.9.2
Disclosed:
Sep 23, 2021

CVE-2021-36823 on NVD →

AGCA &#8211; Custom Dashboard &amp; Login Page [ag-custom-admin] < 6.5.5

unknown

Reflected Cross-Site Scripting (XSS) vulnerability found by Antony Garand (Sucuri) in WordPress Absolutely Glamorous Custom Admin plugin (versions <= 6.5.4).

Affected:
up to 6.5.5
Fixed in:
6.5.5
Disclosed:
Sep 9, 2020

Custom Dashboard & Login Page – AGCA <= 6.5.4 - Reflected Cross-Site Scripting

medium

The Custom Dashboard & Login Page – AGCA plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the tab parameter in versions up to, and including 6.5.4. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in administrative pages that execute if they can successfully t...

CVSS:
6.1
Affected:
up to 6.5.4
Fixed in:
6.5.5
Disclosed:
Sep 8, 2020

AGCA &#8211; Custom Dashboard &amp; Login Page [ag-custom-admin] < 6.5.5

unknown

The Custom Dashboard & Login Page – AGCA plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the tab parameter in versions up to, and including 6.5.4. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in administrative pages that execute if they can successfully t...

Affected:
up to 6.5.5
Fixed in:
6.5.5
Disclosed:
Sep 8, 2020

AGCA &#8211; Custom Dashboard &amp; Login Page [ag-custom-admin] < 6.5.5

unknown

Antony Garand of Sucuri discovered that multiple WordPress plugins were vulnerable to Cross-Site Scripting (XSS) within the admin panel, which could be exploited by using s Cross-Site Request Forgery (CSRF) attack.

Affected:
up to 6.5.5
Fixed in:
6.5.5

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database