SmartText Rotator – Add Motion to Your Words [css3-rotating-words] < 5.5
unknown
[en] Missing Authorization vulnerability in Labib Ahmed Animated Rotating Words allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Animated Rotating Words: from n/a through 5.4.
- Affected:
- up to 5.5
- Fixed in:
- 5.5
- Disclosed:
- Jan 2, 2025
CVE-2023-47187 on NVD →
SmartText Rotator – Add Motion to Your Words [css3-rotating-words] < 5.7
unknown
[en] Cross-Site Request Forgery (CSRF) vulnerability in Labib Ahmed Animated Rotating Words allows Cross Site Request Forgery.This issue affects Animated Rotating Words: from n/a through 5.6.
- Affected:
- up to 5.7
- Fixed in:
- 5.7
- Disclosed:
- Jan 2, 2025
CVE-2024-38753 on NVD →
Dynamic Word Spinner: CSS3 Animated Rotation <= 5.6 - Cross-Site Request Forgery
medium
The Dynamic Word Spinner: CSS3 Animated Rotation plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 5.6. This is due to missing or incorrect nonce validation on the save_admin_options() function. This makes it possible for unauthenticated attackers to update plugin se...
- CVSS:
- 4.3
- Affected:
- up to 5.6
- Fixed in:
- 5.7
- Disclosed:
- Jul 11, 2024
CVE-2024-38753 on NVD →
Animated Rotating Words <= 5.4 - Cross-Site Request Forgery via save_admin_options
medium
The Animated Rotating Words (Interchanging Random Words in a Sentence) plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 5.4. This is due to missing or incorrect nonce validation on the save_admin_options function. This makes it possible for unauthenticated attackers...
- CVSS:
- 4.3
- Affected:
- up to 5.4
- Fixed in:
- 5.5
- Disclosed:
- Nov 3, 2023
CVE-2023-47187 on NVD →
Animated Rotating Words <= 5.4 - Missing Authorization via save_admin_options
medium
The Animated Rotating Words plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the save_admin_options function in versions up to, and including, 5.4. This makes it possible for authenticated attackers, with subscriber-level access and above, to update the plugin...
- CVSS:
- 4.3
- Affected:
- up to 5.4
- Fixed in:
- 5.5
- Disclosed:
- Nov 3, 2023
CVE-2023-47187 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database