CMS Tree Page View [cms-tree-page-view] < 1.6.8
unknown[en] Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Jon Christopher CMS Tree Page View plugin <= 1.6.7 versions.
- Affected:
- up to 1.6.8
- Fixed in:
- 1.6.8
- Disclosed:
- May 18, 2023
plugin
11 known security issues reported for the Cms Tree Page View WordPress plugin. Most recent disclosed May 18, 2023.
Running Cms Tree Page View on your site? Check whether your installed version is affected.
Scan your site free[en] Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Jon Christopher CMS Tree Page View plugin <= 1.6.7 versions.
The CMS Tree Page View plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'post_type' parameter in versions up to, and including, 1.6.7 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that...
The CMS Tree Page View plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'post_type' parameter in versions up to, and including, 1.6.7 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that...
The CMS Tree Page View plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the cms_tpv_move_page function in versions before 1.4. This makes it possible for authenticated attackers with subscriber-level privileges to move pages.
The CMS Tree Page View plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the cms_tpv_move_page function in versions before 1.4. This makes it possible for authenticated attackers with subscriber-level privileges to move pages.
This plugin is prone to page creation cross site request forgery vulnerability. Update the plugin.
This plugin is prone to multiple parameter cross site scripting vulnerability. Update the plugin.
[en] Cross-site scripting (XSS) vulnerability in the cms_tpv_admin_head function in functions.php in the CMS Tree Page View plugin before 0.8.9 for WordPress allows remote attackers to inject arbitrary web script or HTML via the cms_tpv_view parameter to wp-admin/options-general.php.
Cross-site scripting (XSS) vulnerability in the cms_tpv_admin_head function in functions.php in the CMS Tree Page View plugin before 0.8.9 for WordPress allows remote attackers to inject arbitrary web script or HTML via the cms_tpv_view parameter to wp-admin/options-general.php.
The CMS Tree Page View WordPress plugin was affected by a Multiple Parameter XSS security vulnerability.
The CMS Tree Page View WordPress plugin was affected by a Page Creation CSRF security vulnerability.
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free