plugin

Automated Editor Vulnerabilities

2 known security issues reported for the Automated Editor WordPress plugin. Most recent disclosed Oct 13, 2023.

1 medium

Running Automated Editor on your site? Check whether your installed version is affected.

Scan your site free

Automated Editor [automated-editor] <= 1.3 (unfixed + closed)

unknown

[en] Cross-Site Request Forgery (CSRF) vulnerability in automatededitor.Com Automated Editor plugin <= 1.3 versions.

Affected:
up to 1.3
Fix:
No patched version reported
Disclosed:
Oct 13, 2023

CVE-2023-45276 on NVD →

Automated Editor <= 1.3 - Cross-Site Request Forgery via admin menu pages

medium

The Automated Editor plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.3. This is due to missing or incorrect nonce validation on multiple admin menu pages. This makes it possible for unauthenticated attackers to change the plugin's settings via a forged request grante...

CVSS:
4.3
Affected:
up to 1.3
Fix:
No patched version reported
Disclosed:
Oct 6, 2023

CVE-2023-45276 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database