Disable Json API, Login Lockdown, XMLRPC, Pingback, Stop User Enumeration Anti Hacker Scan <= 4.51 - Missing Authorization to Unauthenticated IP Address Whitelist
medium
The Disable Json API, Login Lockdown, XMLRPC, Pingback, Stop User Enumeration Anti Hacker Scan plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the antihacker_add_whitelist() function in all versions up to, and including, 4.51. This makes it possible for unaut...
- CVSS:
- 6.5
- Affected:
- up to 4.51
- Fixed in:
- 4.52
- Disclosed:
- Feb 27, 2024
CVE-2024-1860 on NVD →
Disable Json API, Login Lockdown, XMLRPC, Pingback, Stop User Enumeration Anti Hacker Scan <= 4.52 - Missing Authorization to Authenticated (Subscriber+) Table Truncation
medium
The Disable Json API, Login Lockdown, XMLRPC, Pingback, Stop User Enumeration Anti Hacker Scan plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the antihacker_truncate_scan_table() function in all versions up to, and including, 4.52. This makes it possible for...
- CVSS:
- 4.3
- Affected:
- up to 4.52
- Fixed in:
- 4.53
- Disclosed:
- Feb 27, 2024
CVE-2024-1861 on NVD →
Anti Hacker <= 4.34 - Cross-Site Request Forgery via antihacker_ajax_scan
medium
The Disable Json API, Login Lockdown, XMLRPC, Pingback, Stop User Enumeration Anti Hacker Scan plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to 4.35 (exclusive). This is due to missing or incorrect nonce validation on the 'antihacker_ajax_scan' function. This makes it possible for...
- CVSS:
- 4.3
- Affected:
- up to 4.35
- Fixed in:
- 4.35
- Disclosed:
- Dec 22, 2023
CVE-2023-50858 on NVD →
Anti Hacker <= 4.19 - Missing Authorization to Arbitrary Plugin Install
medium
The Anti Hacker plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the antihacker_install_plugin() function in versions up to, and including, 4.19. This makes it possible for authenticated attackers with minimal permission, such as a subscriber, to install arbitrary plugins...
- CVSS:
- 6.5
- Affected:
- up to 4.19
- Fixed in:
- 4.20
- Disclosed:
- Nov 21, 2022
CVE-2022-3880 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database