plugin

Crony Vulnerabilities

5 known security issues reported for the Crony WordPress plugin. Most recent disclosed Apr 15, 2024.

1 high 1 medium

Running Crony on your site? Check whether your installed version is affected.

Scan your site free

Crony Cronjob Manager [crony] <= 0.5.0 (unfixed + closed)

unknown

[en] Cross-Site Request Forgery (CSRF) vulnerability in Scott Kingsley Clark Crony Cronjob Manager.This issue affects Crony Cronjob Manager: from n/a through 0.5.0.

Affected:
up to 0.5.0
Fix:
No patched version reported
Disclosed:
Apr 15, 2024

CVE-2024-32102 on NVD →

Crony Cronjob Manager <= 0.5.0 - Cross-Site Request Forgery

medium

The Crony Cronjob Manager plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 0.5.0. This is due to missing or incorrect nonce validation on an unknown function. This makes it possible for unauthenticated attackers to perform an unknown action granted they can trick a...

CVSS:
4.3
Affected:
up to 0.5.0
Fix:
No patched version reported
Disclosed:
Apr 11, 2024

CVE-2024-32102 on NVD →

Crony Cronjob Manager [crony] < 0.4.7 (closed)

unknown

[en] WP_Admin_UI in the Crony Cronjob Manager plugin before 0.4.7 for WordPress has CSRF via the name parameter in an action=manage&do=create operation, as demonstrated by inserting XSS sequences.

Affected:
up to 0.4.7
Fixed in:
0.4.7
Disclosed:
Sep 18, 2017

CVE-2017-14530 on NVD →

Crony Cronjob Manager < 0.4.7 - Cross-Site Request Forgery to Stored Cross-Site Scripting

high

WP_Admin_UI in the Crony Cronjob Manager plugin before 0.4.7 for WordPress has CSRF via the name parameter in an action=manage&do=create operation, as demonstrated by inserting XSS sequences.

CVSS:
8.8
Affected:
up to 0.4.7
Fixed in:
0.4.7
Disclosed:
Oct 27, 2015

CVE-2017-14530 on NVD →

Crony Cronjob Manager [crony] < 0.4.6 (closed)

unknown

This plugin is prone to a cross site scripting and cross site request forgery vulnerabilities. Update the plugin.

Affected:
up to 0.4.6
Fixed in:
0.4.6
Disclosed:
Oct 27, 2015

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database