WordPress Landing Page – Squeeze Page – Responsive Landing Page Builder Free – WP Lead Plus X [free-sales-funnel-squeeze-pages-landing-page-builder-templates-make] <= 0.99 (unfixed + closed)
unknown
[en] The WP Lead Plus X plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 0.99. This is due to missing or incorrect nonce validation on several functions. This makes it possible for unauthenticated attackers to perform administrative actions, such as adding pages to the...
- Affected:
- up to 0.99
- Fix:
- No patched version reported
- Disclosed:
- Oct 16, 2024
CVE-2020-36839 on NVD →
WP Lead Plus X <= 0.99 - Cross-Site Request Forgery
high
The WP Lead Plus X plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 0.99. This is due to missing or incorrect nonce validation on several functions. This makes it possible for unauthenticated attackers to perform administrative actions, such as adding pages to the site...
- CVSS:
- 8.3
- Affected:
- up to 0.99
- Fix:
- No patched version reported
- Disclosed:
- Apr 7, 2020
CVE-2020-36839 on NVD →
WP Lead Plus X <= 0.98 - Stored Cross-Site Scripting
high
An XSS vulnerability in the WP Lead Plus X plugin through 0.98 for WordPress allows remote attackers to upload page templates containing arbitrary JavaScript via the c37_wpl_import_template admin-post action (which will execute in an administrator's browser if the template is used to create a page).
- CVSS:
- 7.2
- Affected:
- up to 0.98
- Fixed in:
- 0.99
- Disclosed:
- Apr 7, 2020
CVE-2020-11509 on NVD →
WordPress Landing Page – Squeeze Page – Responsive Landing Page Builder Free – WP Lead Plus X <= 0.98 - Authenticated Stored Cross-Site Scripting
medium
An XSS vulnerability in the WP Lead Plus X plugin through 0.98 for WordPress allows logged-in users with minimal permissions to create or replace existing pages with a malicious page containing arbitrary JavaScript via the wp_ajax_core37_lp_save_page (aka core37_lp_save_page) AJAX action.
- CVSS:
- 5.4
- Affected:
- up to 0.99
- Fixed in:
- 0.99
- Disclosed:
- Apr 7, 2020
CVE-2020-11508 on NVD →
WordPress Landing Page – Squeeze Page – Responsive Landing Page Builder Free – WP Lead Plus X [free-sales-funnel-squeeze-pages-landing-page-builder-templates-make] < 0.99 (closed)
unknown
[en] An XSS vulnerability in the WP Lead Plus X plugin through 0.98 for WordPress allows logged-in users with minimal permissions to create or replace existing pages with a malicious page containing arbitrary JavaScript via the wp_ajax_core37_lp_save_page (aka core37_lp_save_page) AJAX action.
- Affected:
- up to 0.99
- Fixed in:
- 0.99
- Disclosed:
- Apr 7, 2020
CVE-2020-11508 on NVD →
WordPress Landing Page – Squeeze Page – Responsive Landing Page Builder Free – WP Lead Plus X [free-sales-funnel-squeeze-pages-landing-page-builder-templates-make] < 0.99 (closed)
unknown
[en] An XSS vulnerability in the WP Lead Plus X plugin through 0.98 for WordPress allows remote attackers to upload page templates containing arbitrary JavaScript via the c37_wpl_import_template admin-post action (which will execute in an administrator's browser if the template is used to create a page).
- Affected:
- up to 0.99
- Fixed in:
- 0.99
- Disclosed:
- Apr 7, 2020
CVE-2020-11509 on NVD →
WordPress Landing Page – Squeeze Page – Responsive Landing Page Builder Free – WP Lead Plus X [free-sales-funnel-squeeze-pages-landing-page-builder-templates-make] <= 0.99 (unfixed + closed)
unknown
Cross-Site Request Forgery (CSRF) vulnerability discovered by WordFence in WordPress WP Lead Plus X plugin (versions <= 0.99).
- Affected:
- up to 0.99
- Fix:
- No patched version reported
- Disclosed:
- Apr 7, 2020
WordPress Landing Page – Squeeze Page – Responsive Landing Page Builder Free – WP Lead Plus X [free-sales-funnel-squeeze-pages-landing-page-builder-templates-make] <= 0.99 (unfixed)
unknown
None of the functions in this plugin use nonce checks, so it is possible for an attacker to perform any action that the plugin is capable of by tricking an administrator into clicking a specially crafted link designed to perform that action. This includes capabilities such as adding new pages, replacing existing pages,...
- Affected:
- up to 0.99
- Fix:
- No patched version reported
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database