CP Blocks <= 1.0.20 - Cross-Site Request Forgery to Settings Update
medium
The CP Blocks plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.0.20. This is due to incorrect nonce validation in the admin-int-license.inc.php file. This makes it possible for unauthenticated attackers to update the license key via a forged request granted they can t...
- CVSS:
- 4.3
- Affected:
- up to 1.0.20
- Fixed in:
- 1.0.21
- Disclosed:
- Sep 5, 2023
CVE-2023-41732 on NVD →
CP Blocks <= 1.0.14 - Authenticated Stored Cross-Site Scripting via License ID settings
medium
The CP Blocks WordPress plugin before 1.0.15 does not sanitise and escape its "License ID" settings, which could allow high privilege users to inject arbitrary web scripts that execute in a victim's browser even when the unfiltered_html is disallowed.
- CVSS:
- 6.4
- Affected:
- up to 1.0.15
- Fixed in:
- 1.0.15
- Disclosed:
- Feb 2, 2022
CVE-2022-0448 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database