Audio Merchant [audio-merchant] <= 5.0.4 (unfixed + closed)
unknown
[en] The Audio Merchant plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 5.0.4. This is due to missing or incorrect nonce validation on the audio_merchant_save_settings function. This makes it possible for unauthenticated attackers to modify the plugin's settings an...
- Affected:
- up to 5.0.4
- Fix:
- No patched version reported
- Disclosed:
- Nov 20, 2023
CVE-2023-6197 on NVD →
Audio Merchant [audio-merchant] <= 5.0.4 (unfixed + closed)
unknown
[en] The Audio Merchant plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 5.0.4. This is due to missing or incorrect nonce validation on the function audio_merchant_add_audio_file function. This makes it possible for unauthenticated attackers to upload arbitrary file...
- Affected:
- up to 5.0.4
- Fix:
- No patched version reported
- Disclosed:
- Nov 20, 2023
CVE-2023-6196 on NVD →
Audio Merchant <= 5.0.4 - Cross-Site Request Forgery to Arbitrary File Upload
high
The Audio Merchant plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 5.0.4. This is due to missing or incorrect nonce validation on the function audio_merchant_add_audio_file function. This makes it possible for unauthenticated attackers to upload arbitrary files via...
- CVSS:
- 8.8
- Affected:
- up to 5.0.4
- Fix:
- No patched version reported
- Disclosed:
- Nov 17, 2023
CVE-2023-6196 on NVD →
Audio Merchant <= 5.0.4 - Cross-Site Request Forgery to Settings Modifcation and Stored Cross-Site Scripting
medium
The Audio Merchant plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 5.0.4. This is due to missing or incorrect nonce validation on the audio_merchant_save_settings function. This makes it possible for unauthenticated attackers to modify the plugin's settings and inj...
- CVSS:
- 5.4
- Affected:
- up to 5.0.4
- Fix:
- No patched version reported
- Disclosed:
- Nov 17, 2023
CVE-2023-6197 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database