plugin

Divebook Vulnerabilities

6 known security issues reported for the Divebook WordPress plugin. Most recent disclosed Dec 9, 2020.

1 critical 2 medium

Running Divebook on your site? Check whether your installed version is affected.

Scan your site free

DiveBook <= 1.1.4 - Improper Access Control

medium

The DiveBook plugin 1.1.4 for WordPress is prone to improper access control in the Log Dive form because it fails to perform authorization checks. An attacker may leverage this issue to manipulate the integrity of dive logs.

CVSS:
5.3
Affected:
up to 1.1.4
Fix:
No patched version reported
Disclosed:
Dec 9, 2020

CVE-2020-14205 on NVD →

DiveBook [divebook] < 1.5.5 (closed)

unknown

[en] The DiveBook plugin 1.1.4 for WordPress is prone to unauthenticated XSS within the filter function (via an arbitrary parameter).

Affected:
up to 1.5.5
Fixed in:
1.5.5
Disclosed:
Dec 8, 2020

CVE-2020-14206 on NVD →

DiveBook [divebook] < 1.5.5 (closed)

unknown

[en] The DiveBook plugin 1.1.4 for WordPress is prone to improper access control in the Log Dive form because it fails to perform authorization checks. An attacker may leverage this issue to manipulate the integrity of dive logs.

Affected:
up to 1.5.5
Fixed in:
1.5.5
Disclosed:
Dec 8, 2020

CVE-2020-14205 on NVD →

DiveBook [divebook] < 1.5.5 (closed)

unknown

[en] The DiveBook plugin 1.1.4 for WordPress was prone to a SQL injection within divelog.php, allowing unauthenticated users to retrieve data from the database via the divelog.php filter_diver parameter.

Affected:
up to 1.5.5
Fixed in:
1.5.5
Disclosed:
Dec 8, 2020

CVE-2020-14207 on NVD →

DiveBook <= 1.1.4 - SQL Injection

critical

The DiveBook plugin 1.1.4 for WordPress was prone to a SQL injection within divelog.php, allowing unauthenticated users to retrieve data from the database via the divelog.php filter_diver parameter.

CVSS:
9.8
Affected:
up to 1.1.4
Fix:
No patched version reported
Disclosed:
Sep 15, 2020

CVE-2020-14207 on NVD →

DiveBook <= 1.1.4 - Reflected Cross-Site Scripting

medium

The DiveBook plugin 1.1.4 for WordPress is prone to unauthenticated XSS within the filter function (via an arbitrary parameter).

CVSS:
6.1
Affected:
up to 1.1.4
Fix:
No patched version reported
Disclosed:
Sep 15, 2020

CVE-2020-14206 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database