Coru LFMember [coru-lfmember] <= 1.0.2 (unfixed + closed)
unknown
[en] The Coru LFMember WordPress plugin through 1.0.2 does not have CSRF check in place when adding a new game, and is lacking sanitisation as well as escaping in their settings, allowing attacker to make a logged in admin add an arbitrary game with XSS payloads
- Affected:
- up to 1.0.2
- Fix:
- No patched version reported
- Disclosed:
- Jan 16, 2024
CVE-2022-1618 on NVD →
Coru LFMember <= 1.0.2 - Cross-Site Request Forgery
high
The Coru LFMember plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.0.2. This is due to missing or incorrect nonce validation on the /coru-lfmember-game-page.php function. This makes it possible for unauthenticated attackers to delete and activate arbitrary games via a...
- CVSS:
- 8.8
- Affected:
- up to 1.0.2
- Fix:
- No patched version reported
- Disclosed:
- Apr 27, 2022
Coru LFMember <= 1.0.2 - Cross-Site Request Forgery to Stored Cross-Site Scripting
high
The Tracked Tweets plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 0.2.9. This is due to missing nonce validation via the coru_lfmember_admin page. This makes it possible for unauthenticated attackers to modify the plugin's settings and inject arbitrary web scripts via...
- CVSS:
- 8.8
- Affected:
- up to 1.0.2
- Fix:
- No patched version reported
- Disclosed:
- Apr 27, 2022
CVE-2022-1618 on NVD →
Coru LFMember [coru-lfmember] <= 1.0.2 (closed)
unknown
Stored Cross-Site Scripting (XSS) via Cross-Site Request Forgery (CSRF) vulnerability discovered by Mariam Tariq in WordPress Coru LFMember plugin (versions <= 1.0.2).
- Affected:
- up to 1.0.2
- Fixed in:
- 1.0.2
- Disclosed:
- Apr 27, 2022
Coru LFMember [coru-lfmember] <= 1.0.2 (unfixed + closed)
unknown
Arbitrary Game Deletion/Activation via Cross-Site Request Forgery (CSRF) vulnerability discovered by WPScanTeam in WordPress Coru LFMember plugin (versions <= 1.0.2).
- Affected:
- up to 1.0.2
- Fix:
- No patched version reported
- Disclosed:
- Apr 27, 2022
Coru LFMember [coru-lfmember] <= 1.0.2 (unfixed + closed)
unknown
The Coru LFMember plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.0.2. This is due to missing or incorrect nonce validation on the /coru-lfmember-game-page.php function. This makes it possible for unauthenticated attackers to delete and activate arbitrary games via a...
- Affected:
- up to 1.0.2
- Fix:
- No patched version reported
- Disclosed:
- Apr 27, 2022
Coru LFMember [coru-lfmember] <= 1.0.2 (unfixed + closed)
unknown
The plugin does not have CSRF in place when deleting and activating games, which could allow attacker to make a logged in admin perform such actions
- Affected:
- up to 1.0.2
- Fix:
- No patched version reported
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database