plugin

Cool Timeline Vulnerabilities

12 known security issues reported for the Cool Timeline WordPress plugin. Most recent disclosed Jul 1, 2023.

1 high 1 medium

Running Cool Timeline on your site? Check whether your installed version is affected.

Scan your site free

Cool Timeline (Horizontal &amp; Vertical Timeline) [cool-timeline] < 2.0.3

unknown

[en] The Cool Timeline (Horizontal & Vertical Timeline) plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.0.2. This is due to missing or incorrect nonce validation on the ctl_save() function. This makes it possible for unauthenticated attackers to save field icons via...

Affected:
up to 2.0.3
Fixed in:
2.0.3
Disclosed:
Jul 1, 2023

CVE-2020-36738 on NVD →

Cool Timeline (Horizontal &amp; Vertical Timeline) [cool-timeline] < 2.4

unknown

[en] Several WordPress plugins developed by Cool Plugins are vulnerable to arbitrary plugin installation and activation that can lead to remote code execution by authenticated attackers with minimal permissions, such as a subscriber.

Affected:
up to 2.4
Fixed in:
2.4
Disclosed:
Jun 7, 2023

CVE-2022-4950 on NVD →

Cool Timeline (Horizontal &amp; Vertical Timeline) [cool-timeline] < 2.0.3

unknown
Affected:
up to 2.0.3
Fixed in:
2.0.3
Disclosed:
Jun 7, 2023

CVE-2021-4342 on NVD →

Cool Timeline (Horizontal &amp; Vertical Timeline) [cool-timeline] < 2.4

unknown

Arbitrary Plugin Installation vulnerability discovered by Jerome Bruandet (NinTechNet) in WordPress Cool Timeline plugin (versions <= 2.3.3).

Affected:
up to 2.4
Fixed in:
2.4
Disclosed:
Apr 5, 2022

Cool Timeline (Horizontal &amp; Vertical Timeline) [cool-timeline] < 2.4

unknown

Arbitrary Plugin Activation vulnerability discovered by Jerome Bruandet (NinTechNet) in WordPress Cool Timeline plugin (versions <= 2.3.3).

Affected:
up to 2.4
Fixed in:
2.4
Disclosed:
Apr 5, 2022

Cool Plugins (Various Versions) - Arbitrary Plugin Installation and Activation

high

Several WordPress plugins developed by Cool Plugins are vulnerable to arbitrary plugin installation and activation that can lead to remote code execution by authenticated attackers with minimal permissions, such as a subscriber.

CVSS:
8.8
Affected:
up to 2.3.3
Fixed in:
2.4
Disclosed:
Apr 4, 2022

CVE-2022-4950 on NVD →

Cool Timeline (Horizontal &amp; Vertical Timeline) [cool-timeline] < 2.4

unknown

Several WordPress plugins developed by Cool Plugins are vulnerable to arbitrary plugin installation and activation that can lead to remote code execution by authenticated attackers with minimal permissions, such as a subscriber.

Affected:
up to 2.4
Fixed in:
2.4
Disclosed:
Apr 4, 2022

Cool Timeline (Horizontal & Vertical Timeline) <= 2.0.2 - Cross-Site Request Forgery Bypass

medium

The Cool Timeline (Horizontal & Vertical Timeline) plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.0.2. This is due to missing or incorrect nonce validation on the ctl_save() function. This makes it possible for unauthenticated attackers to save field icons via a for...

CVSS:
4.3
Affected:
up to 2.0.3
Fixed in:
2.0.3
Disclosed:
Sep 16, 2020

CVE-2020-36738 on NVD →

Cool Timeline (Horizontal &amp; Vertical Timeline) [cool-timeline] < 2.0.3

unknown

Cross-Site Request Forgery (CSRF) vulnerability found by Jerome Bruandet (NinTechNet) in WordPress Cool Timeline plugin (versions <= 2.0.2).

Affected:
up to 2.0.3
Fixed in:
2.0.3
Disclosed:
Sep 16, 2020

Cool Timeline (Horizontal &amp; Vertical Timeline) [cool-timeline] < 2.0.3

unknown

NinTechNet discovered multiple WordPress plugins and themes vulnerable to Cross-Site Request Forgery (CSRF). The items only check the CSRF nonce if it has been provided, making them vulnerable to CSRF attacks if the nonce is removed. This is due to the confusing use of logic operators when verifying the nonces.

Affected:
up to 2.0.3
Fixed in:
2.0.3

Cool Timeline (Horizontal &amp; Vertical Timeline) [cool-timeline] < 2.4

unknown

Multiple plugins from the Cool Plugins vendor are missing capability and proper CSRF check in the cool_plugins_install and cool_plugins_activate AJAX actions, available to any authenticated users, allowing them to install and activate arbitrary plugins via an archive hosted on a remote server they control

Affected:
up to 2.4
Fixed in:
2.4

Cool Timeline (Horizontal &amp; Vertical Timeline) [cool-timeline] < 2.0.3

unknown

Over 70 plugins and themes were vulnerable to Cross-Site Request Forgery due to improperly implemented nonce protection that could be bypassed.

Affected:
up to 2.0.3
Fixed in:
2.0.3

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database