Cooked Pro [cooked-pro] < 1.8.0
unknown
[en] Cross-Site Request Forgery (CSRF) vulnerability in Gora Tech LLC Cooked Pro allows Cross Site Request Forgery.This issue affects Cooked Pro: from n/a before 1.8.0.
- Affected:
- up to 1.8.0
- Fixed in:
- 1.8.0
- Disclosed:
- Oct 20, 2024
CVE-2024-49290 on NVD →
Cooked Pro [cooked-pro] < 1.8.0
unknown
[en] Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Gora Tech LLC Cooked Pro allows Stored XSS.This issue affects Cooked Pro: from n/a before 1.8.0.
- Affected:
- up to 1.8.0
- Fixed in:
- 1.8.0
- Disclosed:
- Oct 17, 2024
CVE-2024-49289 on NVD →
Cooked Pro [cooked-pro] < 1.8.0
unknown
[en] Unrestricted Upload of File with Dangerous Type vulnerability in Gora Tech LLC Cooked Pro.This issue affects Cooked Pro: from n/a before 1.8.0.
- Affected:
- up to 1.8.0
- Fixed in:
- 1.8.0
- Disclosed:
- Oct 17, 2024
CVE-2024-49291 on NVD →
Cooked Pro < 1.8.0 - Unauthenticated Arbitrary File Upload
critical
The Cooked Pro plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in all versions up to 1.8.0 (exclusive). This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible.
- CVSS:
- 9.8
- Affected:
- up to 1.8.0
- Fixed in:
- 1.8.0
- Disclosed:
- Oct 15, 2024
CVE-2024-49291 on NVD →
Cooked Pro < 1.8.0 - Authenticated (Contributor+) Stored Cross-Site Scripting
medium
The Cooked Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to 1.8.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whe...
- CVSS:
- 6.4
- Affected:
- up to 1.8.0
- Fixed in:
- 1.8.0
- Disclosed:
- Oct 15, 2024
CVE-2024-49289 on NVD →
Cooked Pro < 1.8.0 - Cross-Site Request Forgery
medium
The Cooked Pro plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to 1.8.0. This is due to missing or incorrect nonce validation on a function. This makes it possible for unauthenticated attackers to perform an unauthorized action via a forged request granted they can trick a site administr...
- CVSS:
- 4.3
- Affected:
- up to 1.8.0
- Fixed in:
- 1.8.0
- Disclosed:
- Oct 15, 2024
CVE-2024-49290 on NVD →
Cooked Pro [cooked-pro] < 1.8.0
unknown
[en] The Cooked Pro recipe plugin for WordPress is vulnerable to Persistent Cross-Site Scripting (XSS) via the `_recipe_settings[post_title]` parameter in versions up to, and including, 1.7.15.4 due to insufficient input sanitization and output escaping. This vulnerability allows authenticated attackers with contributo...
- Affected:
- up to 1.8.0
- Fixed in:
- 1.8.0
- Disclosed:
- Jun 13, 2024
CVE-2024-37308 on NVD →
Cooked Pro [cooked-pro] < 1.7.5.7
unknown
[en] The Cooked Pro WordPress plugin before 1.7.5.7 does not properly validate or sanitize the recipe_args parameter before unserializing it in the cooked_loadmore action, allowing an unauthenticated attacker to trigger a PHP Object injection vulnerability.
- Affected:
- up to 1.7.5.7
- Fixed in:
- 1.7.5.7
- Disclosed:
- Dec 12, 2022
CVE-2022-3900 on NVD →
Cooked Pro < 1.7.5.7 - Unauthenticated PHP Object Injection
critical
The Cooked Pro plugin for WordPress is vulnerable to PHP Object Injection in versions up to, but not including, 1.7.5.7 via deserialization of untrusted input from the recipe_args parameter. This allows unauthenticated attackers to inject a PHP Object. If a POP chain is present via an additional plugin or theme install...
- CVSS:
- 9.8
- Affected:
- up to 1.7.5.7
- Fixed in:
- 1.7.5.7
- Disclosed:
- Nov 21, 2022
CVE-2022-3900 on NVD →
Cooked Pro [cooked-pro] < 1.7.5.6
unknown
[en] The Cooked Pro WordPress plugin before 1.7.5.6 was affected by unauthenticated reflected Cross-Site Scripting issues, due to improper sanitisation of user input while being output back in pages as an arbitrary attribute.
- Affected:
- up to 1.7.5.6
- Fixed in:
- 1.7.5.6
- Disclosed:
- Apr 22, 2021
CVE-2021-24233 on NVD →
Cooked Pro <= 1.7.5.5 - Reflected Cross-Site Scripting
medium
The Cooked Pro plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 1.7.5.6 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully tr...
- CVSS:
- 6.1
- Affected:
- up to 1.7.5.6
- Fixed in:
- 1.7.5.6
- Disclosed:
- Mar 30, 2021
CVE-2021-24233 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database