Awesome Filterable Portfolio <= 1.9.7 - Missing Authorization to Plugin Settings Change
high
The Awesome Filterable Portfolio plugin for WordPress is vulnerable to unauthenticated plugin settings change due to missing authentication in versions up to, and including, 1.9.7. This makes it possible for unauthenticated attackers to change them.
- CVSS:
- 7.5
- Affected:
- up to 1.9.7
- Fix:
- No patched version reported
- Disclosed:
- Sep 15, 2022
CVE-2022-35238 on NVD →
Awesome Filterable Portfolio <= 1.9.7 - Unauthenticated Stored Cross-Site Scripting
high
The Awesome Filterable Portfolio plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.9.7 due to insufficient input sanitization and output escaping in several of its functions. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages...
- CVSS:
- 7.2
- Affected:
- up to 1.9.7
- Fix:
- No patched version reported
- Disclosed:
- Sep 15, 2022
CVE-2022-40193 on NVD →
Awesome Filterable Portfolio < 1.9 - Blind SQL Injection
high
The awesome-filterable-portfolio plugin before 1.9 for WordPress has afp_get_new_category_page SQL injection via the cat_id parameter.
- CVSS:
- 7.2
- Affected:
- up to 1.9
- Fixed in:
- 1.9
- Disclosed:
- Jul 7, 2015
CVE-2015-9462 on NVD →
Awesome Filterable Portfolio < 1.9 - Blind SQL Injection
high
The awesome-filterable-portfolio plugin before 1.9 for WordPress has afp_get_new_portfolio_item_page SQL injection via the item_id parameter.
- CVSS:
- 7.2
- Affected:
- up to 1.9
- Fixed in:
- 1.9
- Disclosed:
- Jul 7, 2015
CVE-2015-9461 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database