plugin

Antihacker Vulnerabilities

4 known security issues reported for the Antihacker WordPress plugin. Most recent disclosed Feb 27, 2024.

4 medium

Running Antihacker on your site? Check whether your installed version is affected.

Scan your site free

Disable Json API, Login Lockdown, XMLRPC, Pingback, Stop User Enumeration Anti Hacker Scan <= 4.51 - Missing Authorization to Unauthenticated IP Address Whitelist

medium

The Disable Json API, Login Lockdown, XMLRPC, Pingback, Stop User Enumeration Anti Hacker Scan plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the antihacker_add_whitelist() function in all versions up to, and including, 4.51. This makes it possible for unaut...

CVSS:
6.5
Affected:
up to 4.51
Fixed in:
4.52
Disclosed:
Feb 27, 2024

CVE-2024-1860 on NVD →

Disable Json API, Login Lockdown, XMLRPC, Pingback, Stop User Enumeration Anti Hacker Scan <= 4.52 - Missing Authorization to Authenticated (Subscriber+) Table Truncation

medium

The Disable Json API, Login Lockdown, XMLRPC, Pingback, Stop User Enumeration Anti Hacker Scan plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the antihacker_truncate_scan_table() function in all versions up to, and including, 4.52. This makes it possible for...

CVSS:
4.3
Affected:
up to 4.52
Fixed in:
4.53
Disclosed:
Feb 27, 2024

CVE-2024-1861 on NVD →

Anti Hacker <= 4.34 - Cross-Site Request Forgery via antihacker_ajax_scan

medium

The Disable Json API, Login Lockdown, XMLRPC, Pingback, Stop User Enumeration Anti Hacker Scan plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to 4.35 (exclusive). This is due to missing or incorrect nonce validation on the 'antihacker_ajax_scan' function. This makes it possible for...

CVSS:
4.3
Affected:
up to 4.35
Fixed in:
4.35
Disclosed:
Dec 22, 2023

CVE-2023-50858 on NVD →

Anti Hacker <= 4.19 - Missing Authorization to Arbitrary Plugin Install

medium

The Anti Hacker plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the antihacker_install_plugin() function in versions up to, and including, 4.19. This makes it possible for authenticated attackers with minimal permission, such as a subscriber, to install arbitrary plugins...

CVSS:
6.5
Affected:
up to 4.19
Fixed in:
4.20
Disclosed:
Nov 21, 2022

CVE-2022-3880 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database