DrawBlog [drawblog] <= 0.90 (unfixed + closed)
unknown
[en] The DrawBlog WordPress plugin through 0.90 does not sanitise or validate some of its settings before outputting them back in the page, leading to an authenticated stored Cross-Site Scripting issue
- Affected:
- up to 0.90
- Fix:
- No patched version reported
- Disclosed:
- Aug 2, 2021
CVE-2021-24479 on NVD →
DrawBlog <= 0.90 - Authenticated (Admin+) Stored Cross-Site Scripting
medium
The DrawBlog WordPress plugin through 0.90 does not sanitise or validate some of its settings before outputting them back in the page, leading to an authenticated stored Cross-Site Scripting issue
- CVSS:
- 5.5
- Affected:
- up to 0.90
- Fix:
- No patched version reported
- Disclosed:
- Jun 28, 2021
CVE-2021-24479 on NVD →
DrawBlog [drawblog] < 0.81 (closed)
unknown
This plugin is prone to a cross site request forgery vulnerability.
Upgrade the plugin.
- Affected:
- up to 0.81
- Fixed in:
- 0.81
- Disclosed:
- May 15, 2015
DrawBlog [drawblog] < 0.81 (closed)
unknown
This plugin is prone to a cross site request forgery vulnerability.
Upgrade the plugin.
- Affected:
- up to 0.81
- Fixed in:
- 0.81
- Disclosed:
- May 15, 2015
DrawBlog < 0.81 - Cross-Site Request Forgery
high
The DrawBlog plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions before 0.81. This is due to missing or incorrect nonce validation on the drawblog_update_options function. This makes it possible for unauthenticated attackers to arbitrarily change plugin settings via a forged request granted the...
- CVSS:
- 8.8
- Affected:
- up to 0.81
- Fixed in:
- 0.81
- Disclosed:
- Apr 3, 2013
DrawBlog [drawblog] < 0.81
unknown
The DrawBlog plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions before 0.81. This is due to missing or incorrect nonce validation on the drawblog_update_options function. This makes it possible for unauthenticated attackers to arbitrarily change plugin settings via a forged request granted the...
- Affected:
- up to 0.81
- Fixed in:
- 0.81
- Disclosed:
- Apr 3, 2013
DrawBlog [drawblog] < 0.81
unknown
The DrawBlog WordPress plugin was affected by a CSRF security vulnerability.
- Affected:
- up to 0.81
- Fixed in:
- 0.81
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database