Custom Post Type and Taxonomy GUI Manager [custom-post-type-cpt-cusom-taxonomy-ct-manager] <= 1.1 (unfixed + closed)
unknown
[en] The Custom Post Type and Taxonomy GUI Manager WordPress plugin through 1.1 does not have CSRF, and is lacking sanitising as well as escaping in some parameters, allowing attackers to make a logged in admin put Stored Cross-Site Scripting payloads via CSRF
- Affected:
- up to 1.1
- Fix:
- No patched version reported
- Disclosed:
- Apr 24, 2023
CVE-2023-0420 on NVD →
Custom Post Type and Taxonomy GUI Manager <= 1.1 - Cross-Site Request Forgery to Cross-Site Scripting
medium
The Custom Post Type and Taxonomy GUI Manager for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.1. This is due to missing or incorrect nonce validation when saving settings. This makes it possible for unauthenticated attackers to invoke the vulnerable function via a forged re...
- CVSS:
- 6.1
- Affected:
- up to 1.1
- Fix:
- No patched version reported
- Disclosed:
- Mar 28, 2023
CVE-2023-0420 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database