plugin

Corner Ad Vulnerabilities

7 known security issues reported for the Corner Ad WordPress plugin. Most recent disclosed Dec 15, 2022.

1 high 2 medium

Running Corner Ad on your site? Check whether your installed version is affected.

Scan your site free

Corner Ad [corner-ad] < 1.0.57

unknown

[en] The Corner Ad plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.0.56. This is due to missing or incorrect nonce validation on its corner_ad_settings_page function. This makes it possible for unauthenticated attackers to trigger the deletion of ads via forged reque...

Affected:
up to 1.0.57
Fixed in:
1.0.57
Disclosed:
Dec 15, 2022

CVE-2022-3427 on NVD →

Corner Ad <= 1.0.56 - Cross-Site Request Forgery

high

The Corner Ad plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.0.56. This is due to missing or incorrect nonce validation on its corner_ad_settings_page function. This makes it possible for unauthenticated attackers to trigger the deletion of ads via forged request gr...

CVSS:
8.8
Affected:
up to 1.0.56
Fixed in:
1.0.57
Disclosed:
Sep 9, 2022

CVE-2022-3427 on NVD →

Corner Ad <= 1.0.53 - Reflected Cross-Site Scripting

medium

The Corner Ad plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘codepeople_promote_banner_plugin’ parameter in versions up to, and including, 1.0.53 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web script...

CVSS:
6.1
Affected:
up to 1.0.53
Fixed in:
1.0.54
Disclosed:
Aug 16, 2022

Corner Ad [corner-ad] < 1.0.54

unknown

The Corner Ad plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘codepeople_promote_banner_plugin’ parameter in versions up to, and including, 1.0.53 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web script...

Affected:
up to 1.0.54
Fixed in:
1.0.54
Disclosed:
Aug 16, 2022

Corner Ad [corner-ad] < 1.0.8

unknown

[en] The corner-ad plugin before 1.0.8 for WordPress has XSS.

Affected:
up to 1.0.8
Fixed in:
1.0.8
Disclosed:
Aug 22, 2019

CVE-2017-18579 on NVD →

Corner Ad < 1.0.8 - Cross-Site Scripting

medium

The corner-ad plugin before 1.0.8 for WordPress has XSS.

CVSS:
6.4
Affected:
up to 1.0.8
Fixed in:
1.0.8
Disclosed:
Feb 16, 2017

CVE-2017-18579 on NVD →

Corner Ad [corner-ad] < 1.0.8

unknown

WordPress plugin Corner Ad <= 1.0.7 vulnerable to Cross-Site Scripting due to incorrectly escaped input fields. Possibly affected administrators, users, editors. Update the plugin to the latest version (at least 1.0.8).

Affected:
up to 1.0.8
Fixed in:
1.0.8
Disclosed:
Feb 16, 2017

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database