plugin

Dvs Custom Notification Vulnerabilities

1 known security issue reported for the Dvs Custom Notification WordPress plugin. Most recent disclosed Sep 14, 2012.

1 high

Running Dvs Custom Notification on your site? Check whether your installed version is affected.

Scan your site free

DVS Custom Notification <= 1.0.1 - Cross-Site Request Forgery

high

Multiple cross-site request forgery (CSRF) vulnerabilities in the DVS Custom Notification plugin 1.0.1 and earlier for WordPress allow remote attackers to hijack the authentication of administrators for requests that (1) change application settings or (2) conduct cross-site scripting (XSS) attacks.

CVSS:
8.8
Affected:
up to 1.0.1
Fix:
No patched version reported
Disclosed:
Sep 14, 2012

CVE-2012-4921 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database