Announce from the Dashboard [announce-from-the-dashboard] < 1.5.3
unknown
[en] The Announce from the Dashboard plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 1.5.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and a...
- Affected:
- up to 1.5.3
- Fixed in:
- 1.5.3
- Disclosed:
- Apr 4, 2024
CVE-2024-3030 on NVD →
Announce from the Dashboard <= 1.5.2 - Authenticated (Admin+) Stored Cross-Site Scripting
medium
The Announce from the Dashboard plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 1.5.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above,...
- CVSS:
- 4.4
- Affected:
- up to 1.5.2
- Fixed in:
- 1.5.3
- Disclosed:
- Apr 3, 2024
CVE-2024-3030 on NVD →
Announce from the Dashboard [announce-from-the-dashboard] < 1.5.2
unknown
[en] Auth (admin+) Stored Cross-Site Scripting (XSS) vulnerability in gqevu6bsiz Announce from the Dashboard plugin <= 1.5.1 versions.
- Affected:
- up to 1.5.2
- Fixed in:
- 1.5.2
- Disclosed:
- Apr 7, 2023
CVE-2023-25716 on NVD →
Announce from the Dashboard <= 1.5.1 - Authenticated (Administrator+) Stored Cross-Site Scripting
medium
The Announce from the Dashboard plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versions up to, and including, 1.5.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrative-level permissions and above, to...
- CVSS:
- 4.4
- Affected:
- up to 1.5.1
- Fixed in:
- 1.5.2
- Disclosed:
- Feb 13, 2023
CVE-2023-25716 on NVD →
Announce from the Dashboard [announce-from-the-dashboard] < 1.5.2
unknown
The Announce from the Dashboard plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versions up to, and including, 1.5.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrative-level permissions and above, to...
- Affected:
- up to 1.5.2
- Fixed in:
- 1.5.2
- Disclosed:
- Feb 13, 2023
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database