plugin

Gd Bbpress Attachments Vulnerabilities

13 known security issues reported for the Gd Bbpress Attachments WordPress plugin. Most recent disclosed Nov 20, 2024.

1 high 4 medium

Running Gd Bbpress Attachments on your site? Check whether your installed version is affected.

Scan your site free

GD bbPress Attachments [gd-bbpress-attachments] < 4.7.3

unknown

[en] The GD bbPress Attachments plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and including, 4.7.2. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that exe...

Affected:
up to 4.7.3
Fixed in:
4.7.3
Disclosed:
Nov 20, 2024

CVE-2024-11278 on NVD →

GD bbPress Attachments <= 4.7.2 - Reflected Cross-Site Scripting

medium

The GD bbPress Attachments plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and including, 4.7.2. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute...

CVSS:
6.1
Affected:
up to 4.7.2
Fixed in:
4.7.3
Disclosed:
Nov 19, 2024

CVE-2024-11278 on NVD →

GD bbPress Attachments [gd-bbpress-attachments] < 4.4

unknown

[en] Auth. Stored Cross-Site Scripting (XSS) vulnerability in GD bbPress Attachments plugin <= 4.3.1 on WordPress.

Affected:
up to 4.4
Fixed in:
4.4
Disclosed:
Dec 6, 2022

CVE-2022-45816 on NVD →

GD bbPress Attachments <= 4.3.1 - Authenticated (Administrator+) Stored Cross-Site Scripting

medium

The GD bbPress Attachments plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several parameters in versions up to, and including, 4.3.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to i...

CVSS:
5.5
Affected:
up to 4.3.1
Fixed in:
4.4
Disclosed:
Dec 5, 2022

CVE-2022-45816 on NVD →

GD bbPress Attachments <= 2.5 - Stored Cross-Site Scripting

medium

The GD bbPress Attachments plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘$error[‘file’]’ variable in versions up to, and including, 2.5 due to insufficient input sanitization and output escaping. This makes it possible for authorized attackers to inject arbitrary web scripts in pages that w...

CVSS:
6.4
Affected:
up to 2.5
Fixed in:
2.6
Disclosed:
May 14, 2018

GD bbPress Attachments [gd-bbpress-attachments] < 2.6

unknown

Authenticated Stored Cross-Site Scripting (XSS) vulnerability found by Luigi Gubello in WordPress GD bbPress Attachments plugin (versions <=2.5).

Affected:
up to 2.6
Fixed in:
2.6
Disclosed:
May 14, 2018

GD bbPress Attachments [gd-bbpress-attachments] < 2.6

unknown

The GD bbPress Attachments plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘$error[‘file’]’ variable in versions up to, and including, 2.5 due to insufficient input sanitization and output escaping. This makes it possible for authorized attackers to inject arbitrary web scripts in pages that w...

Affected:
up to 2.6
Fixed in:
2.6
Disclosed:
May 14, 2018

GD bbPress Attachments [gd-bbpress-attachments] < 2.3

unknown

[en] Cross-site scripting (XSS) vulnerability in forms/panels.php in the GD bbPress Attachments plugin before 2.3 for WordPress allows remote attackers to inject arbitrary web script or HTML via the tab parameter in the gdbbpress_attachments page to wp-admin/edit.php.

Affected:
up to 2.3
Fixed in:
2.3
Disclosed:
Aug 18, 2015

CVE-2015-5481 on NVD →

GD bbPress Attachments [gd-bbpress-attachments] < 2.3

unknown

[en] Directory traversal vulnerability in the GD bbPress Attachments plugin before 2.3 for WordPress allows remote administrators to include and execute arbitrary local files via a .. (dot dot) in the tab parameter in the gdbbpress_attachments page to wp-admin/edit.php.

Affected:
up to 2.3
Fixed in:
2.3
Disclosed:
Aug 18, 2015

CVE-2015-5482 on NVD →

GD bbPress Attachments < 2.3 - Directory Traversal

high

Directory traversal vulnerability in the GD bbPress Attachments plugin before 2.3 for WordPress allows remote administrators to include and execute arbitrary local files via a .. (dot dot) in the tab parameter in the gdbbpress_attachments page to wp-admin/edit.php.

CVSS:
7.2
Affected:
up to 2.3
Fixed in:
2.3
Disclosed:
Jul 9, 2015

CVE-2015-5482 on NVD →

GD bbPress Attachments < 2.3 - Reflected Cross-Site Scripting

medium

Cross-site scripting (XSS) vulnerability in forms/panels.php in the GD bbPress Attachments plugin before 2.3 for WordPress allows remote attackers to inject arbitrary web script or HTML via the tab parameter in the gdbbpress_attachments page to wp-admin/edit.php.

CVSS:
6.1
Affected:
up to 2.3
Fixed in:
2.3
Disclosed:
Jul 8, 2015

CVE-2015-5481 on NVD →

GD bbPress Attachments [gd-bbpress-attachments] < 4.4

unknown

Update the WordPress GD bbPress Attachments plugin to the latest available version (at least 4.4). Lana Codes discovered and reported this Cross Site Scripting (XSS) vulnerability in WordPress GD bbPress Attachments Plugin. This could allow a malicious actor to inject malicious scripts, such as redirects, advertisement...

Affected:
up to 4.4
Fixed in:
4.4

GD bbPress Attachments [gd-bbpress-attachments] < 2.6

unknown

An authenticated user of a bbPress forum, who can attach a file, can inject arbitrary JavaScript code via the image filename. The arbitrary code runs both on the topic page and in the admin panel, and it only affects the administrators, moderators and the attacker. The variable $error[&lsquo;file&rsquo;] in /code/at...

Affected:
up to 2.6
Fixed in:
2.6

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database