plugin

Dtracker Vulnerabilities

4 known security issues reported for the Dtracker WordPress plugin. Most recent disclosed Mar 13, 2017.

2 critical 2 high

Running Dtracker on your site? Check whether your installed version is affected.

Scan your site free

Dtracker <= 1.5 - Missing Authorization

high

Vulnerability in wordpress plugin DTracker v1.5, The code dtracker/save_contact.php doesn't check that the user is authorized before injecting new contacts into the wp_contact table.

CVSS:
7.5
Affected:
up to 1.5
Fix:
No patched version reported
Disclosed:
Mar 13, 2017

CVE-2017-1002006 on NVD →

DTracker <= 1.5 - SQL Injection

critical

Vulnerability in wordpress plugin DTracker v1.5, In file ./dtracker/delete.php user input isn't sanitized via the contact_id variable before adding it to the end of an SQL query.

CVSS:
9.8
Affected:
up to 1.5
Fix:
No patched version reported
Disclosed:
Mar 8, 2017

CVE-2017-1002005 on NVD →

DTracker <= 1.5 - SQL Injection

critical

Vulnerability in wordpress plugin DTracker v1.5, In file ./dtracker/download.php user input isn't sanitized via the id variable before adding it to the end of an SQL query.

CVSS:
9.8
Affected:
up to 1.5
Fix:
No patched version reported
Disclosed:
Mar 8, 2017

CVE-2017-1002004 on NVD →

DTracker <= 1.5 - Authorization Bypass

high

Vulnerability in wordpress plugin DTracker v1.5, The code dtracker/save_mail.php doesn't check that the user is authorized before injecting new contacts into the wp_contact table.

CVSS:
7.5
Affected:
up to 1.5
Fix:
No patched version reported
Disclosed:
Mar 8, 2017

CVE-2017-1002007 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database