plugin

Draw Attention Vulnerabilities

4 known security issues reported for the Draw Attention WordPress plugin. Most recent disclosed Jan 2, 2025.

2 medium

Running Draw Attention on your site? Check whether your installed version is affected.

Scan your site free

Interactive Image Map Plugin &#8211; Draw Attention [draw-attention] < 2.0.16

unknown

[en] Missing Authorization vulnerability in NSquared Draw Attention allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Draw Attention: from n/a through 2.0.15.

Affected:
up to 2.0.16
Fixed in:
2.0.16
Disclosed:
Jan 2, 2025

CVE-2023-46616 on NVD →

Draw Attention <= 2.0.15 - Improper Access Control via register_cpt

medium

The Draw Attention plugin for WordPress is vulnerable to unauthorized modification of data due improper capability mapping on the register_cpt function in versions up to, and including, 2.0.15. This makes it possible for authenticated attackers, with contributor-level access and above, to edit other user's Draw Attenti...

CVSS:
6.3
Affected:
up to 2.0.15
Fixed in:
2.0.16
Disclosed:
Oct 24, 2023

CVE-2023-46616 on NVD →

Interactive Image Map Plugin &#8211; Draw Attention [draw-attention] < 2.0.12

unknown

[en] The Draw Attention plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the ajax_set_featured_image function in versions up to, and including, 2.0.11. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to change t...

Affected:
up to 2.0.12
Fixed in:
2.0.12
Disclosed:
Jun 9, 2023

CVE-2023-2764 on NVD →

Draw Attention <= 2.0.11 - Missing Authorization to Arbitrary Post Featured Image Modification

medium

The Draw Attention plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the ajax_set_featured_image function in versions up to, and including, 2.0.11. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to change the fe...

CVSS:
4.3
Affected:
up to 2.0.11
Fixed in:
2.0.12
Disclosed:
May 30, 2023

CVE-2023-2764 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database