FTP Access [ftp-access] <= 1.0 (unfixed + closed)
unknown
[en] The FTP Access WordPress plugin through 1.0 does not have authorisation and CSRF checks when updating its settings and is missing sanitisation as well as escaping in them, allowing any authenticated users, such as subscriber to update them with XSS payloads, which will be triggered when an admin will view the sett...
- Affected:
- up to 1.0
- Fix:
- No patched version reported
- Disclosed:
- Sep 11, 2023
CVE-2023-3510 on NVD →
FTP Access <= 1.0 - Missing Authorization to Authenticated (Subscriber+) Stored Cross-Site Scripting
medium
The FTP Access plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the FTPMenu() function hooked via admin_menu in versions up to, and including, 1.0. This makes it possible for authenticated attackers, with subscriber-level permissions, and above to modify the...
- CVSS:
- 6.4
- Affected:
- up to 1.0
- Fix:
- No patched version reported
- Disclosed:
- Aug 22, 2023
CVE-2023-3510 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database