DiveBook <= 1.1.4 - Improper Access Control
medium
The DiveBook plugin 1.1.4 for WordPress is prone to improper access control in the Log Dive form because it fails to perform authorization checks. An attacker may leverage this issue to manipulate the integrity of dive logs.
- CVSS:
- 5.3
- Affected:
- up to 1.1.4
- Fix:
- No patched version reported
- Disclosed:
- Dec 9, 2020
CVE-2020-14205 on NVD →
DiveBook [divebook] < 1.5.5 (closed)
unknown
[en] The DiveBook plugin 1.1.4 for WordPress is prone to unauthenticated XSS within the filter function (via an arbitrary parameter).
- Affected:
- up to 1.5.5
- Fixed in:
- 1.5.5
- Disclosed:
- Dec 8, 2020
CVE-2020-14206 on NVD →
DiveBook [divebook] < 1.5.5 (closed)
unknown
[en] The DiveBook plugin 1.1.4 for WordPress is prone to improper access control in the Log Dive form because it fails to perform authorization checks. An attacker may leverage this issue to manipulate the integrity of dive logs.
- Affected:
- up to 1.5.5
- Fixed in:
- 1.5.5
- Disclosed:
- Dec 8, 2020
CVE-2020-14205 on NVD →
DiveBook [divebook] < 1.5.5 (closed)
unknown
[en] The DiveBook plugin 1.1.4 for WordPress was prone to a SQL injection within divelog.php, allowing unauthenticated users to retrieve data from the database via the divelog.php filter_diver parameter.
- Affected:
- up to 1.5.5
- Fixed in:
- 1.5.5
- Disclosed:
- Dec 8, 2020
CVE-2020-14207 on NVD →
DiveBook <= 1.1.4 - SQL Injection
critical
The DiveBook plugin 1.1.4 for WordPress was prone to a SQL injection within divelog.php, allowing unauthenticated users to retrieve data from the database via the divelog.php filter_diver parameter.
- CVSS:
- 9.8
- Affected:
- up to 1.1.4
- Fix:
- No patched version reported
- Disclosed:
- Sep 15, 2020
CVE-2020-14207 on NVD →
DiveBook <= 1.1.4 - Reflected Cross-Site Scripting
medium
The DiveBook plugin 1.1.4 for WordPress is prone to unauthenticated XSS within the filter function (via an arbitrary parameter).
- CVSS:
- 6.1
- Affected:
- up to 1.1.4
- Fix:
- No patched version reported
- Disclosed:
- Sep 15, 2020
CVE-2020-14206 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database