plugin

Exit Strategy Vulnerabilities

2 known security issues reported for the Exit Strategy WordPress plugin. Most recent disclosed May 28, 2013.

2 medium

Running Exit Strategy on your site? Check whether your installed version is affected.

Scan your site free

WordPress Exit Strategy <= 1.55 - Information Exposure

medium

The WordPress Exit Strategy plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 1.55. This is due the plugin not properly restricting direct access to the exitpage.php file. This makes it possible for unauthenticated attackers to retrieve the full path of the web application...

CVSS:
5.3
Affected:
up to 1.55
Fixed in:
1.59
Disclosed:
May 28, 2013

CVE-2013-10024 on NVD →

WordPress Exit Strategy <= 1.55 - Cross-Site Request Forgery

medium

The exit-strategy plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.55. This is due to missing or incorrect nonce validation on the exit_page_admin() function. This makes it possible for unauthenticated attackers to modify the plugin's settings via a forged request...

CVSS:
4.3
Affected:
up to 1.55
Fixed in:
1.59
Disclosed:
May 28, 2013

CVE-2013-10025 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database