plugin

Drawblog Vulnerabilities

7 known security issues reported for the Drawblog WordPress plugin. Most recent disclosed Aug 2, 2021.

1 high 1 medium

Running Drawblog on your site? Check whether your installed version is affected.

Scan your site free

DrawBlog [drawblog] <= 0.90 (unfixed + closed)

unknown

[en] The DrawBlog WordPress plugin through 0.90 does not sanitise or validate some of its settings before outputting them back in the page, leading to an authenticated stored Cross-Site Scripting issue

Affected:
up to 0.90
Fix:
No patched version reported
Disclosed:
Aug 2, 2021

CVE-2021-24479 on NVD →

DrawBlog <= 0.90 - Authenticated (Admin+) Stored Cross-Site Scripting

medium

The DrawBlog WordPress plugin through 0.90 does not sanitise or validate some of its settings before outputting them back in the page, leading to an authenticated stored Cross-Site Scripting issue

CVSS:
5.5
Affected:
up to 0.90
Fix:
No patched version reported
Disclosed:
Jun 28, 2021

CVE-2021-24479 on NVD →

DrawBlog [drawblog] < 0.81 (closed)

unknown

This plugin is prone to a cross site request forgery vulnerability. Upgrade the plugin.

Affected:
up to 0.81
Fixed in:
0.81
Disclosed:
May 15, 2015

DrawBlog [drawblog] < 0.81 (closed)

unknown

This plugin is prone to a cross site request forgery vulnerability. Upgrade the plugin.

Affected:
up to 0.81
Fixed in:
0.81
Disclosed:
May 15, 2015

DrawBlog < 0.81 - Cross-Site Request Forgery

high

The DrawBlog plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions before 0.81. This is due to missing or incorrect nonce validation on the drawblog_update_options function. This makes it possible for unauthenticated attackers to arbitrarily change plugin settings via a forged request granted the...

CVSS:
8.8
Affected:
up to 0.81
Fixed in:
0.81
Disclosed:
Apr 3, 2013

DrawBlog [drawblog] < 0.81

unknown

The DrawBlog plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions before 0.81. This is due to missing or incorrect nonce validation on the drawblog_update_options function. This makes it possible for unauthenticated attackers to arbitrarily change plugin settings via a forged request granted the...

Affected:
up to 0.81
Fixed in:
0.81
Disclosed:
Apr 3, 2013

DrawBlog [drawblog] < 0.81

unknown

The DrawBlog WordPress plugin was affected by a CSRF security vulnerability.

Affected:
up to 0.81
Fixed in:
0.81

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database