AGCA – Custom Dashboard & Login Page [ag-custom-admin] < 7.2.4
unknown
[en] Server-Side Request Forgery (SSRF) vulnerability in Cusmin Absolutely Glamorous Custom Admin.This issue affects Absolutely Glamorous Custom Admin: from n/a through 7.2.2.
- Affected:
- up to 7.2.4
- Fixed in:
- 7.2.4
- Disclosed:
- Apr 29, 2024
CVE-2024-33627 on NVD →
AGCA – Custom Dashboard & Login Page [ag-custom-admin] < 7.2.2
unknown
[en] The AGCA WordPress plugin before 7.2.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).
- Affected:
- up to 7.2.2
- Fixed in:
- 7.2.2
- Disclosed:
- Apr 25, 2024
CVE-2024-2907 on NVD →
Absolutely Glamorous Custom Admin <= 7.2.3 - Authenticated (Admin+) Server-Side Request Forgery
medium
The AGCA – Custom Dashboard & Login Page plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 7.2.3. This makes it possible for authenticated attackers, with administrator-level access and above, to make web requests to arbitrary locations originating from the web appl...
- CVSS:
- 5.5
- Affected:
- up to 7.2.3
- Fixed in:
- 7.2.4
- Disclosed:
- Apr 24, 2024
CVE-2024-33627 on NVD →
AGCA – Custom Dashboard & Login Page <= 7.2.1 - Authenticated (Admin+) Stored Cross-Site Scripting
medium
The AGCA – Custom Dashboard & Login Page plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 7.2.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions a...
- CVSS:
- 4.4
- Affected:
- up to 7.2.1
- Fixed in:
- 7.2.2
- Disclosed:
- Apr 4, 2024
CVE-2024-2907 on NVD →
AGCA – Custom Dashboard & Login Page [ag-custom-admin] < 7.0
unknown
[en] The Custom Dashboard & Login Page WordPress plugin before 7.0 does not sanitise some of its settings, allowing high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.
- Affected:
- up to 7.0
- Fixed in:
- 7.0
- Disclosed:
- Feb 1, 2022
CVE-2021-24944 on NVD →
Custom Dashboard & Login Page < 6.9.5 - Admin+ Stored Cross-Site Scripting
medium
The Custom Dashboard & Login Page WordPress plugin before 7.0 does not sanitise some of its settings, allowing high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.
- CVSS:
- 4.8
- Affected:
- up to 6.9.5
- Fixed in:
- 7.0
- Disclosed:
- Dec 30, 2021
CVE-2021-24944 on NVD →
Absolutely Glamorous Custom Admin <= 6.8 - Authenticated Stored Cross-Site Scripting
medium
Authenticated Stored Cross-Site Scripting (XSS) vulnerability in WordPress Absolutely Glamorous Custom Admin plugin (versions <= 6.8). Stored XSS possible via unsanitized input fields of the plugin settings, some of the payloads could make the frontend and the backend inaccessible.
- CVSS:
- 6.6
- Affected:
- up to 6.8
- Fixed in:
- 6.9
- Disclosed:
- Sep 23, 2021
CVE-2021-36823 on NVD →
AGCA – Custom Dashboard & Login Page [ag-custom-admin] < 6.9.2
unknown
[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Cusmin AGCA - Absolutely Glamorous Custom Admin (WordPress plugin) allows Stored XSS.This issue affects AGCA - Absolutely Glamorous Custom Admin (WordPress plugin): from n/a through 6.8.
- Affected:
- up to 6.9.2
- Fixed in:
- 6.9.2
- Disclosed:
- Sep 23, 2021
CVE-2021-36823 on NVD →
AGCA – Custom Dashboard & Login Page [ag-custom-admin] < 6.5.5
unknown
Reflected Cross-Site Scripting (XSS) vulnerability found by Antony Garand (Sucuri) in WordPress Absolutely Glamorous Custom Admin plugin (versions <= 6.5.4).
- Affected:
- up to 6.5.5
- Fixed in:
- 6.5.5
- Disclosed:
- Sep 9, 2020
Custom Dashboard & Login Page – AGCA <= 6.5.4 - Reflected Cross-Site Scripting
medium
The Custom Dashboard & Login Page – AGCA plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the tab parameter in versions up to, and including 6.5.4. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in administrative pages that execute if they can successfully t...
- CVSS:
- 6.1
- Affected:
- up to 6.5.4
- Fixed in:
- 6.5.5
- Disclosed:
- Sep 8, 2020
AGCA – Custom Dashboard & Login Page [ag-custom-admin] < 6.5.5
unknown
The Custom Dashboard & Login Page – AGCA plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the tab parameter in versions up to, and including 6.5.4. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in administrative pages that execute if they can successfully t...
- Affected:
- up to 6.5.5
- Fixed in:
- 6.5.5
- Disclosed:
- Sep 8, 2020
AGCA – Custom Dashboard & Login Page [ag-custom-admin] < 6.5.5
unknown
Antony Garand of Sucuri discovered that multiple WordPress plugins were vulnerable to Cross-Site Scripting (XSS) within the admin panel, which could be exploited by using s Cross-Site Request Forgery (CSRF) attack.
- Affected:
- up to 6.5.5
- Fixed in:
- 6.5.5
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database