plugin

Futurio Extra Vulnerabilities

8 known security issues reported for the Futurio Extra WordPress plugin. Most recent disclosed Dec 2, 2024.

1 high 7 medium

Running Futurio Extra on your site? Check whether your installed version is affected.

Scan your site free

Futurio Extra <= 2.0.14 - Authenticated (Contributor+) Stored Cross-Site Scripting via header_size tag

medium

The Futurio Extra plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.0.14 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages t...

CVSS:
6.4
Affected:
up to 2.0.14
Fixed in:
2.0.15
Disclosed:
Dec 2, 2024

CVE-2024-53802 on NVD →

Futurio Extra <= 2.0.13 - Authenticated (Contributor+) Post Disclosure

medium

The Futurio Extra plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 2.0.13 via the 'elementor-template' shortcode due to insufficient restrictions on which posts can be included. This makes it possible for authenticated attackers, with Contributor-level access and above, t...

CVSS:
4.3
Affected:
up to 2.0.13
Fixed in:
2.0.14
Disclosed:
Nov 11, 2024

CVE-2024-10695 on NVD →

Futurio Extra <= 2.0.11 - Authenticated (Contributor+) Stored Cross-Site Scripting

medium

The Futurio Extra plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.0.11 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages t...

CVSS:
6.4
Affected:
up to 2.0.11
Fixed in:
2.0.12
Disclosed:
Oct 24, 2024

CVE-2024-50446 on NVD →

Futurio Extra <= 2.0.5 - Authenticated (Contributor+) Stored Cross-Site Scripting via Advanced Text Block Widget

medium

The Futurio Extra plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘header_size’ attribute within the Advanced Text Block widget in all versions up to, and including, 2.0.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contr...

CVSS:
6.4
Affected:
up to 2.0.5
Fixed in:
2.0.6
Disclosed:
Jun 11, 2024

CVE-2024-5646 on NVD →

Futurio Extra <= 1.9.0 - Cross-Site Request Forgery

medium

The Futurio Extra plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.9.0. This is due to missing or incorrect nonce validation on the futurio_ajax_required_plugins_activate function. This makes it possible for unauthenticated attackers to activate plugins required by Fu...

CVSS:
4.3
Affected:
up to 1.9.0
Fixed in:
1.9.1
Disclosed:
Aug 11, 2023

CVE-2023-40201 on NVD →

Futurio Extra <= 1.8.2 - Cross-Site Request Forgery via 'futurio_extra_reset_mod'

medium

The Futurio Extra plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.8.2. This is due to missing or incorrect nonce validation on the 'futurio_extra_reset_mod' function. This makes it possible for unauthenticated attackers to reset theme modifications via a forged reque...

CVSS:
4.3
Affected:
up to 1.8.2
Fixed in:
1.8.3
Disclosed:
Aug 11, 2023

CVE-2023-40201 on NVD →

Futurio Extra <= 1.6.2 - Sensitive Information Disclosure

medium

The Futurio Extra WordPress plugin before 1.6.3 allows any logged in user, such as subscriber, to extract any other user's email address.

CVSS:
4.3
Affected:
up to 1.6.3
Fixed in:
1.6.3
Disclosed:
Jan 14, 2022

CVE-2021-25110 on NVD →

Futurio Extra <= 1.6.2 - Authenticated (Admin+) SQL Injection

high

The Futurio Extra WordPress plugin before 1.6.3 is affected by a SQL Injection vulnerability that could be used by high privilege users to extract data from the database as well as used to perform Cross-Site Scripting (XSS) against logged in admins by making send open a malicious link.

CVSS:
7.2
Affected:
up to 1.6.3
Fixed in:
1.6.3
Disclosed:
Jan 4, 2022

CVE-2021-25109 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database