WordPress Flipbook by Supsystic [digital-publications-by-supsystic] < 1.7.8 (closed)
unknown
[en] Missing Authorization vulnerability in Supsystic Digital Publications by Supsystic.This issue affects Digital Publications by Supsystic: from n/a through 1.7.7.
- Affected:
- up to 1.7.8
- Fixed in:
- 1.7.8
- Disclosed:
- May 6, 2024
CVE-2024-33910 on NVD →
Digital Publications by Supsystic <= 1.7.7 - Missing Authorization
medium
The WordPress Flipbook by Supsystic plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 1.7.7. This makes it possible for unauthenticated attackers to perform an unauthorized action.
- CVSS:
- 5.3
- Affected:
- up to 1.7.7
- Fixed in:
- 1.7.8
- Disclosed:
- Apr 29, 2024
CVE-2024-33910 on NVD →
WordPress Flipbook by Supsystic [digital-publications-by-supsystic] < 1.7.8 (closed)
unknown
[en] Cross-Site Request Forgery (CSRF) vulnerability in Supsystic Digital Publications by Supsystic.This issue affects Digital Publications by Supsystic: from n/a through 1.7.7.
- Affected:
- up to 1.7.8
- Fixed in:
- 1.7.8
- Disclosed:
- Apr 15, 2024
CVE-2024-32089 on NVD →
Digital Publications by Supsystic <= 1.7.7 - Cross-Site Request Forgery
medium
The WordPress Flipbook by Supsystic plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.7.7. This is due to missing or incorrect nonce validation on an unknown function. This makes it possible for unauthenticated attackers to perform an unknown action granted they ca...
- CVSS:
- 4.3
- Affected:
- up to 1.7.7
- Fixed in:
- 1.7.8
- Disclosed:
- Apr 11, 2024
CVE-2024-32089 on NVD →
WordPress Flipbook by Supsystic [digital-publications-by-supsystic] < 1.7.7 (closed)
unknown
[en] The Digital Publications by Supsystic plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.7.6. This is due to missing or incorrect nonce validation on the AJAX action handler. This makes it possible for unauthenticated attackers to execute AJAX actions via a forged...
- Affected:
- up to 1.7.7
- Fixed in:
- 1.7.7
- Disclosed:
- Dec 9, 2023
CVE-2023-5756 on NVD →
Digital Publications by Supsystic <= 1.7.6 - Cross-Site Request Forgery via AJAX action
medium
The Digital Publications by Supsystic plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.7.6. This is due to missing or incorrect nonce validation on the AJAX action handler. This makes it possible for unauthenticated attackers to execute AJAX actions via a forged reque...
- CVSS:
- 5.4
- Affected:
- up to 1.7.6
- Fixed in:
- 1.7.7
- Disclosed:
- Dec 8, 2023
CVE-2023-5756 on NVD →
WordPress Flipbook by Supsystic [digital-publications-by-supsystic] < 1.7.4 (closed)
unknown
[en] The Digital Publications by Supsystic WordPress plugin before 1.7.4 does not sanitise and escape its settings, allowing high privilege users such as admin to perform cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.
- Affected:
- up to 1.7.4
- Fixed in:
- 1.7.4
- Disclosed:
- Aug 15, 2022
CVE-2022-2384 on NVD →
Digital Publications by Supsystic <= 1.7.3 - Authenticated (Admin+) Stored Cross-Site Scripting
medium
The Digital Publications by Supsystic plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several parameters in versions up to, and including, 1.7.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers with administrative privileges to inject a...
- CVSS:
- 5.5
- Affected:
- up to 1.7.3
- Fixed in:
- 1.7.4
- Disclosed:
- Jul 21, 2022
Digital Publications by Supsystic <= 1.7.3 - Authenticated (Administrator+) Stored Cross-Site Scripting
medium
The Digital Publications by Supsystic WordPress plugin before 1.7.4 does not sanitise and escape its settings, allowing high privilege users such as admin to perform cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.
- CVSS:
- 5.5
- Affected:
- up to 1.7.3
- Fixed in:
- 1.7.4
- Disclosed:
- Jul 21, 2022
CVE-2022-2384 on NVD →
WordPress Flipbook by Supsystic [digital-publications-by-supsystic] < 1.7.4 (closed)
unknown
The Digital Publications by Supsystic plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several parameters in versions up to, and including, 1.7.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers with administrative privileges to inject a...
- Affected:
- up to 1.7.4
- Fixed in:
- 1.7.4
- Disclosed:
- Jul 21, 2022
Digital Publications by Supsystic <= 1.6.12 - Stored Cross-Site Scripting
medium
The Digital Publications by Supsystic plugin for WordPress is vulnerable to Stored Cross-Site Scripting via all of the input fields when editing a publication in versions up to, and including, 1.6.12 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers to inject...
- CVSS:
- 6.4
- Affected:
- up to 1.6.12
- Fixed in:
- 1.7.0
- Disclosed:
- Feb 8, 2021
WordPress Flipbook by Supsystic [digital-publications-by-supsystic] < 1.6.12 (closed)
unknown
Path Traversal and DoS vulnerability found by Erik David Martin in WordPress Digital Publications by Supsystic plugin (versions <= 1.6.11).
- Affected:
- up to 1.6.12
- Fixed in:
- 1.6.12
- Disclosed:
- Feb 8, 2021
WordPress Flipbook by Supsystic [digital-publications-by-supsystic] < 1.7.0 (closed)
unknown
Stored Cross-Site Scripting (XSS) vulnerability found by Erik David Martin in WordPress Digital Publications by Supsystic plugin (versions <= 1.6.12).
- Affected:
- up to 1.7.0
- Fixed in:
- 1.7.0
- Disclosed:
- Feb 8, 2021
WordPress Flipbook by Supsystic [digital-publications-by-supsystic] < 1.7.0 (closed)
unknown
The Digital Publications by Supsystic plugin for WordPress is vulnerable to Stored Cross-Site Scripting via all of the input fields when editing a publication in versions up to, and including, 1.6.12 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers to inject...
- Affected:
- up to 1.7.0
- Fixed in:
- 1.7.0
- Disclosed:
- Feb 8, 2021
WordPress Flipbook by Supsystic [digital-publications-by-supsystic] < 1.6.12 (closed)
unknown
- Affected:
- up to 1.6.12
- Fixed in:
- 1.6.12
WordPress Flipbook by Supsystic [digital-publications-by-supsystic] < 1.7.0 (closed)
unknown
When creating or editing a publication, all values such as Area Width, Publication Width are vulnerable to stored XSS. It is possible to store code in all input fields as the code does not sanitize any user input.
v1.6.11 attempted to fix the issue by using sanitize_text_field(), however the output is put in an attr...
- Affected:
- up to 1.7.0
- Fixed in:
- 1.7.0
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database