Interactive Image Map Plugin – Draw Attention [draw-attention] < 2.0.16
unknown
[en] Missing Authorization vulnerability in NSquared Draw Attention allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Draw Attention: from n/a through 2.0.15.
- Affected:
- up to 2.0.16
- Fixed in:
- 2.0.16
- Disclosed:
- Jan 2, 2025
CVE-2023-46616 on NVD →
Draw Attention <= 2.0.15 - Improper Access Control via register_cpt
medium
The Draw Attention plugin for WordPress is vulnerable to unauthorized modification of data due improper capability mapping on the register_cpt function in versions up to, and including, 2.0.15. This makes it possible for authenticated attackers, with contributor-level access and above, to edit other user's Draw Attenti...
- CVSS:
- 6.3
- Affected:
- up to 2.0.15
- Fixed in:
- 2.0.16
- Disclosed:
- Oct 24, 2023
CVE-2023-46616 on NVD →
Interactive Image Map Plugin – Draw Attention [draw-attention] < 2.0.12
unknown
[en] The Draw Attention plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the ajax_set_featured_image function in versions up to, and including, 2.0.11. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to change t...
- Affected:
- up to 2.0.12
- Fixed in:
- 2.0.12
- Disclosed:
- Jun 9, 2023
CVE-2023-2764 on NVD →
Draw Attention <= 2.0.11 - Missing Authorization to Arbitrary Post Featured Image Modification
medium
The Draw Attention plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the ajax_set_featured_image function in versions up to, and including, 2.0.11. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to change the fe...
- CVSS:
- 4.3
- Affected:
- up to 2.0.11
- Fixed in:
- 2.0.12
- Disclosed:
- May 30, 2023
CVE-2023-2764 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database