WordPress Robots.txt optimizer (+ XML Sitemap) – Boost SEO, Traffic & Rankings [better-robots-txt] < 1.4.4
unknown
[en] The Freemius SDK, as used by hundreds of WordPress plugin and theme developers, was vulnerable to Cross-Site Request Forgery and Information disclosure due to missing capability checks and nonce protection on the _get_debug_log, _get_db_option, and the _set_db_option functions in versions up to, and including 2.4....
- Affected:
- up to 1.4.4
- Fixed in:
- 1.4.4
- Disclosed:
- Oct 16, 2024
CVE-2022-4974 on NVD →
WordPress Robots.txt optimizer (+ XML Sitemap) – Boost SEO, Traffic & Rankings [better-robots-txt] < 1.4.6
unknown
[en] Cross-Site Request Forgery (CSRF) vulnerability in Pagup WordPress Robots.Txt optimization plugin <= 1.4.5 versions.
- Affected:
- up to 1.4.6
- Fixed in:
- 1.4.6
- Disclosed:
- Jul 11, 2023
CVE-2023-25706 on NVD →
Robots.txt optimization <= 1.4.5 - Cross Site Request Forgery
medium
The Robots.txt optimization plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.4.5. This is due to missing nonce validation on the page function. This makes it possible for unauthenticated attackers to modify the settings for the plugin, granted they can trick a site ad...
- CVSS:
- 5.4
- Affected:
- up to 1.4.5
- Fixed in:
- 1.4.6
- Disclosed:
- Feb 14, 2023
CVE-2023-25706 on NVD →
Freemius SDK <= 2.4.2 - Missing Authorization Checks
medium
The Freemius SDK, as used by hundreds of WordPress plugin and theme developers, was vulnerable to Cross-Site Request Forgery and Information disclosure due to missing capability checks and nonce protection on the _get_debug_log, _get_db_option, and the _set_db_option functions in versions up to, and including 2.4.2. An...
- CVSS:
- 6.3
- Affected:
- up to 1.4.4
- Fixed in:
- 1.4.4
- Disclosed:
- Mar 4, 2022
CVE-2022-4974 on NVD →
WordPress Robots.txt optimizer (+ XML Sitemap) – Boost SEO, Traffic & Rankings [better-robots-txt] < 1.4.4
unknown
The Freemius SDK, as used by hundreds of WordPress plugin and theme developers, was vulnerable to Cross-Site Request Forgery and Information disclosure due to missing capability checks and nonce protection on the _get_debug_log, _get_db_option, and the _set_db_option functions in versions up to, and including 2.4.2. An...
- Affected:
- up to 1.4.4
- Fixed in:
- 1.4.4
- Disclosed:
- Mar 4, 2022
WordPress Robots.txt optimizer (+ XML Sitemap) – Boost SEO, Traffic & Rankings [better-robots-txt] < 1.4.4
unknown
Toggle The Debug Mode via Cross-Site Request Forgery (CSRF) vulnerability discovered in WordPress "WordPress Robots.txt optimization (+ XML Sitemap) – Website traffic, SEO & ranking Booster" plugin (versions < 1.4.4).
- Affected:
- up to 1.4.4
- Fixed in:
- 1.4.4
- Disclosed:
- Feb 28, 2022
WordPress Robots.txt optimizer (+ XML Sitemap) – Boost SEO, Traffic & Rankings [better-robots-txt] < 1.4.4
unknown
Sensitive Information Disclosure vulnerability discovered in WordPress "WordPress Robots.txt optimization (+ XML Sitemap) – Website traffic, SEO & ranking Booster" plugin (versions < 1.4.4).
- Affected:
- up to 1.4.4
- Fixed in:
- 1.4.4
- Disclosed:
- Feb 28, 2022
Freemius SDK <= 2.2.3 - Missing Authorization to Arbitrary Options Update
high
The Freemius SDK for WordPress is vulnerable to authorization bypass due to a missing capability check on the _get_db_option and _set_db_option functions in versions up to, and including, 2.2.3. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to change site settings and...
- CVSS:
- 8.8
- Affected:
- up to 1.2.6
- Fixed in:
- 1.2.6
- Disclosed:
- Feb 25, 2019
WordPress Robots.txt optimizer (+ XML Sitemap) – Boost SEO, Traffic & Rankings [better-robots-txt] < 1.2.6
unknown
The Freemius SDK for WordPress is vulnerable to authorization bypass due to a missing capability check on the _get_db_option and _set_db_option functions in versions up to, and including, 2.2.3. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to change site settings and...
- Affected:
- up to 1.2.6
- Fixed in:
- 1.2.6
- Disclosed:
- Feb 25, 2019
WordPress Robots.txt optimizer (+ XML Sitemap) – Boost SEO, Traffic & Rankings [better-robots-txt] < 1.2.6
unknown
The library, used in numerous plugins, does not have proper authorisation when updating blog options, allowing any authenticated users, such as subscriber to update arbitrary options
- Affected:
- up to 1.2.6
- Fixed in:
- 1.2.6
WordPress Robots.txt optimizer (+ XML Sitemap) – Boost SEO, Traffic & Rankings [better-robots-txt] < 1.4.7
unknown
** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.
- Affected:
- up to 1.4.7
- Fixed in:
- 1.4.7
CVE-2023-33999 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database