plugin

Business Card By Esterox 100 Vulnerabilities

10 known security issues reported for the Business Card By Esterox 100 WordPress plugin. Most recent disclosed Jul 30, 2024.

1 high 4 medium

Running Business Card By Esterox 100 on your site? Check whether your installed version is affected.

Scan your site free

Business Card [business-card-by-esterox-100] <= 1.0.0 (unfixed + closed)

unknown

[en] The Business Card WordPress plugin through 1.0.0 does not prevent high privilege users like administrators from uploading malicious PHP files, which could allow them to run arbitrary code on servers hosting their site, even in MultiSite configurations.

Affected:
up to 1.0.0
Fix:
No patched version reported
Disclosed:
Jul 30, 2024

CVE-2024-5807 on NVD →

Business Card <= 1.0.0 - Authenticated (Admin+) Arbitrary File Uplaod

high

The Business Card plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the admin_view.php file in all versions up to, and including, 1.0.0. This makes it possible for authenticated attackers, with Administrator-level access and above, to upload arbitrary files on the affec...

CVSS:
7.2
Affected:
up to 1.0.0
Fix:
No patched version reported
Disclosed:
Jul 9, 2024

CVE-2024-5807 on NVD →

Business Card [business-card-by-esterox-100] <= 1.0.0 (unfixed + closed)

unknown

[en] The Business Card WordPress plugin through 1.0.0 does not have CSRF checks in some places, which could allow attackers to make logged in users perform unwanted actions such as deleting card categories via CSRF attacks

Affected:
up to 1.0.0
Fix:
No patched version reported
Disclosed:
May 27, 2024

CVE-2024-4529 on NVD →

Business Card [business-card-by-esterox-100] <= 1.0.0 (unfixed + closed)

unknown

[en] The Business Card WordPress plugin through 1.0.0 does not have CSRF checks in some places, which could allow attackers to make logged in users perform unwanted actions such as editing card categories via CSRF attacks

Affected:
up to 1.0.0
Fix:
No patched version reported
Disclosed:
May 27, 2024

CVE-2024-4530 on NVD →

Business Card [business-card-by-esterox-100] <= 1.0.0 (unfixed + closed)

unknown

[en] The Business Card WordPress plugin through 1.0.0 does not have CSRF checks in some places, which could allow attackers to make logged in users perform unwanted actions such as deleting cards via CSRF attacks

Affected:
up to 1.0.0
Fix:
No patched version reported
Disclosed:
May 27, 2024

CVE-2024-4532 on NVD →

Business Card [business-card-by-esterox-100] <= 1.0.0 (unfixed + closed)

unknown

[en] The Business Card WordPress plugin through 1.0.0 does not have CSRF checks in some places, which could allow attackers to make logged in users perform unwanted actions such as editing cards via CSRF attacks

Affected:
up to 1.0.0
Fix:
No patched version reported
Disclosed:
May 27, 2024

CVE-2024-4531 on NVD →

Business Card <= 1.0.0 - Cross-Site Request Forgery to Arbitrary Card Deletion

medium

The Business Card plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.0. This is due to missing or incorrect nonce validation on a function. This makes it possible for unauthenticated attackers to delete arbitrary cards via a forged request granted they can trick a...

CVSS:
4.3
Affected:
up to 1.0.0
Fix:
No patched version reported
Disclosed:
May 6, 2024

CVE-2024-4532 on NVD →

Business Card <= 1.0.0 - Cross-Site Request Forgery to Category Edit

medium

The Business Card plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.0. This is due to missing or incorrect nonce validation on a function. This makes it possible for unauthenticated attackers to edit categories via a forged request granted they can trick a site a...

CVSS:
4.3
Affected:
up to 1.0.0
Fix:
No patched version reported
Disclosed:
May 6, 2024

CVE-2024-4530 on NVD →

Business Card <= 1.0.0 - Cross-Site Request Forgery to Card Edit

medium

The Business Card plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.0. This is due to missing or incorrect nonce validation on a function. This makes it possible for unauthenticated attackers to edit cards via a forged request granted they can trick a site admini...

CVSS:
4.3
Affected:
up to 1.0.0
Fix:
No patched version reported
Disclosed:
May 6, 2024

CVE-2024-4531 on NVD →

Business Card <= 1.0.0 - Cross-Site Request Forgery to Category Deletion

medium

The Business Card plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.0. This is due to missing or incorrect nonce validation on a function. This makes it possible for unauthenticated attackers to delete categories via a forged request granted they can trick a site...

CVSS:
4.3
Affected:
up to 1.0.0
Fix:
No patched version reported
Disclosed:
May 6, 2024

CVE-2024-4529 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database