Cool Timeline (Horizontal & Vertical Timeline) [cool-timeline] < 2.0.3
unknown
[en] The Cool Timeline (Horizontal & Vertical Timeline) plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.0.2. This is due to missing or incorrect nonce validation on the ctl_save() function. This makes it possible for unauthenticated attackers to save field icons via...
- Affected:
- up to 2.0.3
- Fixed in:
- 2.0.3
- Disclosed:
- Jul 1, 2023
CVE-2020-36738 on NVD →
Cool Timeline (Horizontal & Vertical Timeline) [cool-timeline] < 2.4
unknown
[en] Several WordPress plugins developed by Cool Plugins are vulnerable to arbitrary plugin installation and activation that can lead to remote code execution by authenticated attackers with minimal permissions, such as a subscriber.
- Affected:
- up to 2.4
- Fixed in:
- 2.4
- Disclosed:
- Jun 7, 2023
CVE-2022-4950 on NVD →
Cool Timeline (Horizontal & Vertical Timeline) [cool-timeline] < 2.0.3
unknown
- Affected:
- up to 2.0.3
- Fixed in:
- 2.0.3
- Disclosed:
- Jun 7, 2023
CVE-2021-4342 on NVD →
Cool Timeline (Horizontal & Vertical Timeline) [cool-timeline] < 2.4
unknown
Arbitrary Plugin Installation vulnerability discovered by Jerome Bruandet (NinTechNet) in WordPress Cool Timeline plugin (versions <= 2.3.3).
- Affected:
- up to 2.4
- Fixed in:
- 2.4
- Disclosed:
- Apr 5, 2022
Cool Timeline (Horizontal & Vertical Timeline) [cool-timeline] < 2.4
unknown
Arbitrary Plugin Activation vulnerability discovered by Jerome Bruandet (NinTechNet) in WordPress Cool Timeline plugin (versions <= 2.3.3).
- Affected:
- up to 2.4
- Fixed in:
- 2.4
- Disclosed:
- Apr 5, 2022
Cool Plugins (Various Versions) - Arbitrary Plugin Installation and Activation
high
Several WordPress plugins developed by Cool Plugins are vulnerable to arbitrary plugin installation and activation that can lead to remote code execution by authenticated attackers with minimal permissions, such as a subscriber.
- CVSS:
- 8.8
- Affected:
- up to 2.3.3
- Fixed in:
- 2.4
- Disclosed:
- Apr 4, 2022
CVE-2022-4950 on NVD →
Cool Timeline (Horizontal & Vertical Timeline) [cool-timeline] < 2.4
unknown
Several WordPress plugins developed by Cool Plugins are vulnerable to arbitrary plugin installation and activation that can lead to remote code execution by authenticated attackers with minimal permissions, such as a subscriber.
- Affected:
- up to 2.4
- Fixed in:
- 2.4
- Disclosed:
- Apr 4, 2022
Cool Timeline (Horizontal & Vertical Timeline) <= 2.0.2 - Cross-Site Request Forgery Bypass
medium
The Cool Timeline (Horizontal & Vertical Timeline) plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.0.2. This is due to missing or incorrect nonce validation on the ctl_save() function. This makes it possible for unauthenticated attackers to save field icons via a for...
- CVSS:
- 4.3
- Affected:
- up to 2.0.3
- Fixed in:
- 2.0.3
- Disclosed:
- Sep 16, 2020
CVE-2020-36738 on NVD →
Cool Timeline (Horizontal & Vertical Timeline) [cool-timeline] < 2.0.3
unknown
Cross-Site Request Forgery (CSRF) vulnerability found by Jerome Bruandet (NinTechNet) in WordPress Cool Timeline plugin (versions <= 2.0.2).
- Affected:
- up to 2.0.3
- Fixed in:
- 2.0.3
- Disclosed:
- Sep 16, 2020
Cool Timeline (Horizontal & Vertical Timeline) [cool-timeline] < 2.0.3
unknown
NinTechNet discovered multiple WordPress plugins and themes vulnerable to Cross-Site Request Forgery (CSRF).
The items only check the CSRF nonce if it has been provided, making them vulnerable to CSRF attacks if the nonce is removed. This is due to the confusing use of logic operators when verifying the nonces.
- Affected:
- up to 2.0.3
- Fixed in:
- 2.0.3
Cool Timeline (Horizontal & Vertical Timeline) [cool-timeline] < 2.4
unknown
Multiple plugins from the Cool Plugins vendor are missing capability and proper CSRF check in the cool_plugins_install and cool_plugins_activate AJAX actions, available to any authenticated users, allowing them to install and activate arbitrary plugins via an archive hosted on a remote server they control
- Affected:
- up to 2.4
- Fixed in:
- 2.4
Cool Timeline (Horizontal & Vertical Timeline) [cool-timeline] < 2.0.3
unknown
Over 70 plugins and themes were vulnerable to Cross-Site Request Forgery due to improperly implemented nonce protection that could be bypassed.
- Affected:
- up to 2.0.3
- Fixed in:
- 2.0.3
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database