plugin

Ftp Access Vulnerabilities

2 known security issues reported for the Ftp Access WordPress plugin. Most recent disclosed Sep 11, 2023.

1 medium

Running Ftp Access on your site? Check whether your installed version is affected.

Scan your site free

FTP Access [ftp-access] <= 1.0 (unfixed + closed)

unknown

[en] The FTP Access WordPress plugin through 1.0 does not have authorisation and CSRF checks when updating its settings and is missing sanitisation as well as escaping in them, allowing any authenticated users, such as subscriber to update them with XSS payloads, which will be triggered when an admin will view the sett...

Affected:
up to 1.0
Fix:
No patched version reported
Disclosed:
Sep 11, 2023

CVE-2023-3510 on NVD →

FTP Access <= 1.0 - Missing Authorization to Authenticated (Subscriber+) Stored Cross-Site Scripting

medium

The FTP Access plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the FTPMenu() function hooked via admin_menu in versions up to, and including, 1.0. This makes it possible for authenticated attackers, with subscriber-level permissions, and above to modify the...

CVSS:
6.4
Affected:
up to 1.0
Fix:
No patched version reported
Disclosed:
Aug 22, 2023

CVE-2023-3510 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database