plugin

Crazy Bone Vulnerabilities

2 known security issues reported for the Crazy Bone WordPress plugin. Most recent disclosed Jan 31, 2022.

2 high

Running Crazy Bone on your site? Check whether your installed version is affected.

Scan your site free

Crazy Bone <= 0.6.0 - Unauthenticated Stored Cross-Site Scripting

high

The Crazy Bone WordPress plugin through 0.6.0 does not sanitise and escape the username submitted via the login from when displaying them back in the log dashboard, leading to an unauthenticated Stored Cross-Site scripting

CVSS:
7.2
Affected:
up to 0.6.0
Fix:
No patched version reported
Disclosed:
Jan 31, 2022

CVE-2022-0385 on NVD →

Crazy Bone < 0.6.0 - Stored Cross-Site Scripting

high

The crazy-bone plugin before 0.6.0 for WordPress has XSS via the User-Agent HTTP header

CVSS:
7.2
Affected:
up to 0.6.0
Fixed in:
0.6.0
Disclosed:
Aug 21, 2015

CVE-2015-9430 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database