plugin

Digital Publications By Supsystic Vulnerabilities

16 known security issues reported for the Digital Publications By Supsystic WordPress plugin. Most recent disclosed May 6, 2024.

6 medium

Running Digital Publications By Supsystic on your site? Check whether your installed version is affected.

Scan your site free

WordPress Flipbook by Supsystic [digital-publications-by-supsystic] < 1.7.8 (closed)

unknown

[en] Missing Authorization vulnerability in Supsystic Digital Publications by Supsystic.This issue affects Digital Publications by Supsystic: from n/a through 1.7.7.

Affected:
up to 1.7.8
Fixed in:
1.7.8
Disclosed:
May 6, 2024

CVE-2024-33910 on NVD →

Digital Publications by Supsystic <= 1.7.7 - Missing Authorization

medium

The WordPress Flipbook by Supsystic plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 1.7.7. This makes it possible for unauthenticated attackers to perform an unauthorized action.

CVSS:
5.3
Affected:
up to 1.7.7
Fixed in:
1.7.8
Disclosed:
Apr 29, 2024

CVE-2024-33910 on NVD →

WordPress Flipbook by Supsystic [digital-publications-by-supsystic] < 1.7.8 (closed)

unknown

[en] Cross-Site Request Forgery (CSRF) vulnerability in Supsystic Digital Publications by Supsystic.This issue affects Digital Publications by Supsystic: from n/a through 1.7.7.

Affected:
up to 1.7.8
Fixed in:
1.7.8
Disclosed:
Apr 15, 2024

CVE-2024-32089 on NVD →

Digital Publications by Supsystic <= 1.7.7 - Cross-Site Request Forgery

medium

The WordPress Flipbook by Supsystic plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.7.7. This is due to missing or incorrect nonce validation on an unknown function. This makes it possible for unauthenticated attackers to perform an unknown action granted they ca...

CVSS:
4.3
Affected:
up to 1.7.7
Fixed in:
1.7.8
Disclosed:
Apr 11, 2024

CVE-2024-32089 on NVD →

WordPress Flipbook by Supsystic [digital-publications-by-supsystic] < 1.7.7 (closed)

unknown

[en] The Digital Publications by Supsystic plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.7.6. This is due to missing or incorrect nonce validation on the AJAX action handler. This makes it possible for unauthenticated attackers to execute AJAX actions via a forged...

Affected:
up to 1.7.7
Fixed in:
1.7.7
Disclosed:
Dec 9, 2023

CVE-2023-5756 on NVD →

Digital Publications by Supsystic <= 1.7.6 - Cross-Site Request Forgery via AJAX action

medium

The Digital Publications by Supsystic plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.7.6. This is due to missing or incorrect nonce validation on the AJAX action handler. This makes it possible for unauthenticated attackers to execute AJAX actions via a forged reque...

CVSS:
5.4
Affected:
up to 1.7.6
Fixed in:
1.7.7
Disclosed:
Dec 8, 2023

CVE-2023-5756 on NVD →

WordPress Flipbook by Supsystic [digital-publications-by-supsystic] < 1.7.4 (closed)

unknown

[en] The Digital Publications by Supsystic WordPress plugin before 1.7.4 does not sanitise and escape its settings, allowing high privilege users such as admin to perform cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.

Affected:
up to 1.7.4
Fixed in:
1.7.4
Disclosed:
Aug 15, 2022

CVE-2022-2384 on NVD →

Digital Publications by Supsystic <= 1.7.3 - Authenticated (Admin+) Stored Cross-Site Scripting

medium

The Digital Publications by Supsystic plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several parameters in versions up to, and including, 1.7.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers with administrative privileges to inject a...

CVSS:
5.5
Affected:
up to 1.7.3
Fixed in:
1.7.4
Disclosed:
Jul 21, 2022

Digital Publications by Supsystic <= 1.7.3 - Authenticated (Administrator+) Stored Cross-Site Scripting

medium

The Digital Publications by Supsystic WordPress plugin before 1.7.4 does not sanitise and escape its settings, allowing high privilege users such as admin to perform cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.

CVSS:
5.5
Affected:
up to 1.7.3
Fixed in:
1.7.4
Disclosed:
Jul 21, 2022

CVE-2022-2384 on NVD →

WordPress Flipbook by Supsystic [digital-publications-by-supsystic] < 1.7.4 (closed)

unknown

The Digital Publications by Supsystic plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several parameters in versions up to, and including, 1.7.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers with administrative privileges to inject a...

Affected:
up to 1.7.4
Fixed in:
1.7.4
Disclosed:
Jul 21, 2022

Digital Publications by Supsystic <= 1.6.12 - Stored Cross-Site Scripting

medium

The Digital Publications by Supsystic plugin for WordPress is vulnerable to Stored Cross-Site Scripting via all of the input fields when editing a publication in versions up to, and including, 1.6.12 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers to inject...

CVSS:
6.4
Affected:
up to 1.6.12
Fixed in:
1.7.0
Disclosed:
Feb 8, 2021

WordPress Flipbook by Supsystic [digital-publications-by-supsystic] < 1.6.12 (closed)

unknown

Path Traversal and DoS vulnerability found by Erik David Martin in WordPress Digital Publications by Supsystic plugin (versions <= 1.6.11).

Affected:
up to 1.6.12
Fixed in:
1.6.12
Disclosed:
Feb 8, 2021

WordPress Flipbook by Supsystic [digital-publications-by-supsystic] < 1.7.0 (closed)

unknown

Stored Cross-Site Scripting (XSS) vulnerability found by Erik David Martin in WordPress Digital Publications by Supsystic plugin (versions <= 1.6.12).

Affected:
up to 1.7.0
Fixed in:
1.7.0
Disclosed:
Feb 8, 2021

WordPress Flipbook by Supsystic [digital-publications-by-supsystic] < 1.7.0 (closed)

unknown

The Digital Publications by Supsystic plugin for WordPress is vulnerable to Stored Cross-Site Scripting via all of the input fields when editing a publication in versions up to, and including, 1.6.12 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers to inject...

Affected:
up to 1.7.0
Fixed in:
1.7.0
Disclosed:
Feb 8, 2021

WordPress Flipbook by Supsystic [digital-publications-by-supsystic] < 1.6.12 (closed)

unknown
Affected:
up to 1.6.12
Fixed in:
1.6.12

WordPress Flipbook by Supsystic [digital-publications-by-supsystic] < 1.7.0 (closed)

unknown

When creating or editing a publication, all values such as Area Width, Publication Width are vulnerable to stored XSS. It is possible to store code in all input fields as the code does not sanitize any user input. v1.6.11 attempted to fix the issue by using sanitize_text_field(), however the output is put in an attr...

Affected:
up to 1.7.0
Fixed in:
1.7.0

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database