WordPress Exit Strategy <= 1.55 - Information Exposure
medium
The WordPress Exit Strategy plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 1.55. This is due the plugin not properly restricting direct access to the exitpage.php file. This makes it possible for unauthenticated attackers to retrieve the full path of the web application...
- CVSS:
- 5.3
- Affected:
- up to 1.55
- Fixed in:
- 1.59
- Disclosed:
- May 28, 2013
CVE-2013-10024 on NVD →
WordPress Exit Strategy <= 1.55 - Cross-Site Request Forgery
medium
The exit-strategy plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.55. This is due to missing or incorrect nonce validation on the exit_page_admin() function. This makes it possible for unauthenticated attackers to modify the plugin's settings via a forged request...
- CVSS:
- 4.3
- Affected:
- up to 1.55
- Fixed in:
- 1.59
- Disclosed:
- May 28, 2013
CVE-2013-10025 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database