plugin

Better Robots Txt Vulnerabilities

11 known security issues reported for the Better Robots Txt WordPress plugin. Most recent disclosed Oct 16, 2024.

1 high 2 medium

Running Better Robots Txt on your site? Check whether your installed version is affected.

Scan your site free

WordPress Robots.txt optimizer (+ XML Sitemap) – Boost SEO, Traffic &amp; Rankings [better-robots-txt] < 1.4.4

unknown

[en] The Freemius SDK, as used by hundreds of WordPress plugin and theme developers, was vulnerable to Cross-Site Request Forgery and Information disclosure due to missing capability checks and nonce protection on the _get_debug_log, _get_db_option, and the _set_db_option functions in versions up to, and including 2.4....

Affected:
up to 1.4.4
Fixed in:
1.4.4
Disclosed:
Oct 16, 2024

CVE-2022-4974 on NVD →

WordPress Robots.txt optimizer (+ XML Sitemap) – Boost SEO, Traffic &amp; Rankings [better-robots-txt] < 1.4.6

unknown

[en] Cross-Site Request Forgery (CSRF) vulnerability in Pagup WordPress Robots.Txt optimization plugin <= 1.4.5 versions.

Affected:
up to 1.4.6
Fixed in:
1.4.6
Disclosed:
Jul 11, 2023

CVE-2023-25706 on NVD →

Robots.txt optimization <= 1.4.5 - Cross Site Request Forgery

medium

The Robots.txt optimization plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.4.5. This is due to missing nonce validation on the page function. This makes it possible for unauthenticated attackers to modify the settings for the plugin, granted they can trick a site ad...

CVSS:
5.4
Affected:
up to 1.4.5
Fixed in:
1.4.6
Disclosed:
Feb 14, 2023

CVE-2023-25706 on NVD →

Freemius SDK <= 2.4.2 - Missing Authorization Checks

medium

The Freemius SDK, as used by hundreds of WordPress plugin and theme developers, was vulnerable to Cross-Site Request Forgery and Information disclosure due to missing capability checks and nonce protection on the _get_debug_log, _get_db_option, and the _set_db_option functions in versions up to, and including 2.4.2. An...

CVSS:
6.3
Affected:
up to 1.4.4
Fixed in:
1.4.4
Disclosed:
Mar 4, 2022

CVE-2022-4974 on NVD →

WordPress Robots.txt optimizer (+ XML Sitemap) – Boost SEO, Traffic &amp; Rankings [better-robots-txt] < 1.4.4

unknown

The Freemius SDK, as used by hundreds of WordPress plugin and theme developers, was vulnerable to Cross-Site Request Forgery and Information disclosure due to missing capability checks and nonce protection on the _get_debug_log, _get_db_option, and the _set_db_option functions in versions up to, and including 2.4.2. An...

Affected:
up to 1.4.4
Fixed in:
1.4.4
Disclosed:
Mar 4, 2022

WordPress Robots.txt optimizer (+ XML Sitemap) – Boost SEO, Traffic &amp; Rankings [better-robots-txt] < 1.4.4

unknown

Toggle The Debug Mode via Cross-Site Request Forgery (CSRF) vulnerability discovered in WordPress "WordPress Robots.txt optimization (+ XML Sitemap) – Website traffic, SEO & ranking Booster" plugin (versions < 1.4.4).

Affected:
up to 1.4.4
Fixed in:
1.4.4
Disclosed:
Feb 28, 2022

WordPress Robots.txt optimizer (+ XML Sitemap) – Boost SEO, Traffic &amp; Rankings [better-robots-txt] < 1.4.4

unknown

Sensitive Information Disclosure vulnerability discovered in WordPress "WordPress Robots.txt optimization (+ XML Sitemap) – Website traffic, SEO & ranking Booster" plugin (versions < 1.4.4).

Affected:
up to 1.4.4
Fixed in:
1.4.4
Disclosed:
Feb 28, 2022

Freemius SDK <= 2.2.3 - Missing Authorization to Arbitrary Options Update

high

The Freemius SDK for WordPress is vulnerable to authorization bypass due to a missing capability check on the _get_db_option and _set_db_option functions in versions up to, and including, 2.2.3. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to change site settings and...

CVSS:
8.8
Affected:
up to 1.2.6
Fixed in:
1.2.6
Disclosed:
Feb 25, 2019

WordPress Robots.txt optimizer (+ XML Sitemap) – Boost SEO, Traffic &amp; Rankings [better-robots-txt] < 1.2.6

unknown

The Freemius SDK for WordPress is vulnerable to authorization bypass due to a missing capability check on the _get_db_option and _set_db_option functions in versions up to, and including, 2.2.3. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to change site settings and...

Affected:
up to 1.2.6
Fixed in:
1.2.6
Disclosed:
Feb 25, 2019

WordPress Robots.txt optimizer (+ XML Sitemap) – Boost SEO, Traffic &amp; Rankings [better-robots-txt] < 1.2.6

unknown

The library, used in numerous plugins, does not have proper authorisation when updating blog options, allowing any authenticated users, such as subscriber to update arbitrary options

Affected:
up to 1.2.6
Fixed in:
1.2.6

WordPress Robots.txt optimizer (+ XML Sitemap) – Boost SEO, Traffic &amp; Rankings [better-robots-txt] < 1.4.7

unknown

** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.

Affected:
up to 1.4.7
Fixed in:
1.4.7

CVE-2023-33999 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database