Business Card [business-card-by-esterox-100] <= 1.0.0 (unfixed + closed)
unknown
[en] The Business Card WordPress plugin through 1.0.0 does not prevent high privilege users like administrators from uploading malicious PHP files, which could allow them to run arbitrary code on servers hosting their site, even in MultiSite configurations.
- Affected:
- up to 1.0.0
- Fix:
- No patched version reported
- Disclosed:
- Jul 30, 2024
CVE-2024-5807 on NVD →
Business Card <= 1.0.0 - Authenticated (Admin+) Arbitrary File Uplaod
high
The Business Card plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the admin_view.php file in all versions up to, and including, 1.0.0. This makes it possible for authenticated attackers, with Administrator-level access and above, to upload arbitrary files on the affec...
- CVSS:
- 7.2
- Affected:
- up to 1.0.0
- Fix:
- No patched version reported
- Disclosed:
- Jul 9, 2024
CVE-2024-5807 on NVD →
Business Card [business-card-by-esterox-100] <= 1.0.0 (unfixed + closed)
unknown
[en] The Business Card WordPress plugin through 1.0.0 does not have CSRF checks in some places, which could allow attackers to make logged in users perform unwanted actions such as deleting card categories via CSRF attacks
- Affected:
- up to 1.0.0
- Fix:
- No patched version reported
- Disclosed:
- May 27, 2024
CVE-2024-4529 on NVD →
Business Card [business-card-by-esterox-100] <= 1.0.0 (unfixed + closed)
unknown
[en] The Business Card WordPress plugin through 1.0.0 does not have CSRF checks in some places, which could allow attackers to make logged in users perform unwanted actions such as editing card categories via CSRF attacks
- Affected:
- up to 1.0.0
- Fix:
- No patched version reported
- Disclosed:
- May 27, 2024
CVE-2024-4530 on NVD →
Business Card [business-card-by-esterox-100] <= 1.0.0 (unfixed + closed)
unknown
[en] The Business Card WordPress plugin through 1.0.0 does not have CSRF checks in some places, which could allow attackers to make logged in users perform unwanted actions such as deleting cards via CSRF attacks
- Affected:
- up to 1.0.0
- Fix:
- No patched version reported
- Disclosed:
- May 27, 2024
CVE-2024-4532 on NVD →
Business Card [business-card-by-esterox-100] <= 1.0.0 (unfixed + closed)
unknown
[en] The Business Card WordPress plugin through 1.0.0 does not have CSRF checks in some places, which could allow attackers to make logged in users perform unwanted actions such as editing cards via CSRF attacks
- Affected:
- up to 1.0.0
- Fix:
- No patched version reported
- Disclosed:
- May 27, 2024
CVE-2024-4531 on NVD →
Business Card <= 1.0.0 - Cross-Site Request Forgery to Arbitrary Card Deletion
medium
The Business Card plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.0. This is due to missing or incorrect nonce validation on a function. This makes it possible for unauthenticated attackers to delete arbitrary cards via a forged request granted they can trick a...
- CVSS:
- 4.3
- Affected:
- up to 1.0.0
- Fix:
- No patched version reported
- Disclosed:
- May 6, 2024
CVE-2024-4532 on NVD →
Business Card <= 1.0.0 - Cross-Site Request Forgery to Category Edit
medium
The Business Card plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.0. This is due to missing or incorrect nonce validation on a function. This makes it possible for unauthenticated attackers to edit categories via a forged request granted they can trick a site a...
- CVSS:
- 4.3
- Affected:
- up to 1.0.0
- Fix:
- No patched version reported
- Disclosed:
- May 6, 2024
CVE-2024-4530 on NVD →
Business Card <= 1.0.0 - Cross-Site Request Forgery to Card Edit
medium
The Business Card plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.0. This is due to missing or incorrect nonce validation on a function. This makes it possible for unauthenticated attackers to edit cards via a forged request granted they can trick a site admini...
- CVSS:
- 4.3
- Affected:
- up to 1.0.0
- Fix:
- No patched version reported
- Disclosed:
- May 6, 2024
CVE-2024-4531 on NVD →
Business Card <= 1.0.0 - Cross-Site Request Forgery to Category Deletion
medium
The Business Card plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.0. This is due to missing or incorrect nonce validation on a function. This makes it possible for unauthenticated attackers to delete categories via a forged request granted they can trick a site...
- CVSS:
- 4.3
- Affected:
- up to 1.0.0
- Fix:
- No patched version reported
- Disclosed:
- May 6, 2024
CVE-2024-4529 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database