GD bbPress Attachments [gd-bbpress-attachments] < 4.7.3
unknown
[en] The GD bbPress Attachments plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and including, 4.7.2. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that exe...
- Affected:
- up to 4.7.3
- Fixed in:
- 4.7.3
- Disclosed:
- Nov 20, 2024
CVE-2024-11278 on NVD →
GD bbPress Attachments <= 4.7.2 - Reflected Cross-Site Scripting
medium
The GD bbPress Attachments plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and including, 4.7.2. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute...
- CVSS:
- 6.1
- Affected:
- up to 4.7.2
- Fixed in:
- 4.7.3
- Disclosed:
- Nov 19, 2024
CVE-2024-11278 on NVD →
GD bbPress Attachments [gd-bbpress-attachments] < 4.4
unknown
[en] Auth. Stored Cross-Site Scripting (XSS) vulnerability in GD bbPress Attachments plugin <= 4.3.1 on WordPress.
- Affected:
- up to 4.4
- Fixed in:
- 4.4
- Disclosed:
- Dec 6, 2022
CVE-2022-45816 on NVD →
GD bbPress Attachments <= 4.3.1 - Authenticated (Administrator+) Stored Cross-Site Scripting
medium
The GD bbPress Attachments plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several parameters in versions up to, and including, 4.3.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to i...
- CVSS:
- 5.5
- Affected:
- up to 4.3.1
- Fixed in:
- 4.4
- Disclosed:
- Dec 5, 2022
CVE-2022-45816 on NVD →
GD bbPress Attachments <= 2.5 - Stored Cross-Site Scripting
medium
The GD bbPress Attachments plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘$error[‘file’]’ variable in versions up to, and including, 2.5 due to insufficient input sanitization and output escaping. This makes it possible for authorized attackers to inject arbitrary web scripts in pages that w...
- CVSS:
- 6.4
- Affected:
- up to 2.5
- Fixed in:
- 2.6
- Disclosed:
- May 14, 2018
GD bbPress Attachments [gd-bbpress-attachments] < 2.6
unknown
Authenticated Stored Cross-Site Scripting (XSS) vulnerability found by Luigi Gubello in WordPress GD bbPress Attachments plugin (versions <=2.5).
- Affected:
- up to 2.6
- Fixed in:
- 2.6
- Disclosed:
- May 14, 2018
GD bbPress Attachments [gd-bbpress-attachments] < 2.6
unknown
The GD bbPress Attachments plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘$error[‘file’]’ variable in versions up to, and including, 2.5 due to insufficient input sanitization and output escaping. This makes it possible for authorized attackers to inject arbitrary web scripts in pages that w...
- Affected:
- up to 2.6
- Fixed in:
- 2.6
- Disclosed:
- May 14, 2018
GD bbPress Attachments [gd-bbpress-attachments] < 2.3
unknown
[en] Cross-site scripting (XSS) vulnerability in forms/panels.php in the GD bbPress Attachments plugin before 2.3 for WordPress allows remote attackers to inject arbitrary web script or HTML via the tab parameter in the gdbbpress_attachments page to wp-admin/edit.php.
- Affected:
- up to 2.3
- Fixed in:
- 2.3
- Disclosed:
- Aug 18, 2015
CVE-2015-5481 on NVD →
GD bbPress Attachments [gd-bbpress-attachments] < 2.3
unknown
[en] Directory traversal vulnerability in the GD bbPress Attachments plugin before 2.3 for WordPress allows remote administrators to include and execute arbitrary local files via a .. (dot dot) in the tab parameter in the gdbbpress_attachments page to wp-admin/edit.php.
- Affected:
- up to 2.3
- Fixed in:
- 2.3
- Disclosed:
- Aug 18, 2015
CVE-2015-5482 on NVD →
GD bbPress Attachments < 2.3 - Directory Traversal
high
Directory traversal vulnerability in the GD bbPress Attachments plugin before 2.3 for WordPress allows remote administrators to include and execute arbitrary local files via a .. (dot dot) in the tab parameter in the gdbbpress_attachments page to wp-admin/edit.php.
- CVSS:
- 7.2
- Affected:
- up to 2.3
- Fixed in:
- 2.3
- Disclosed:
- Jul 9, 2015
CVE-2015-5482 on NVD →
GD bbPress Attachments < 2.3 - Reflected Cross-Site Scripting
medium
Cross-site scripting (XSS) vulnerability in forms/panels.php in the GD bbPress Attachments plugin before 2.3 for WordPress allows remote attackers to inject arbitrary web script or HTML via the tab parameter in the gdbbpress_attachments page to wp-admin/edit.php.
- CVSS:
- 6.1
- Affected:
- up to 2.3
- Fixed in:
- 2.3
- Disclosed:
- Jul 8, 2015
CVE-2015-5481 on NVD →
GD bbPress Attachments [gd-bbpress-attachments] < 4.4
unknown
Update the WordPress GD bbPress Attachments plugin to the latest available version (at least 4.4).
Lana Codes discovered and reported this Cross Site Scripting (XSS) vulnerability in WordPress GD bbPress Attachments Plugin. This could allow a malicious actor to inject malicious scripts, such as redirects, advertisement...
- Affected:
- up to 4.4
- Fixed in:
- 4.4
GD bbPress Attachments [gd-bbpress-attachments] < 2.6
unknown
An authenticated user of a bbPress forum, who can attach a file, can inject arbitrary JavaScript code via the image filename. The arbitrary code runs both on the topic page and in the admin panel, and it only affects the administrators, moderators and the attacker.
The variable $error[‘file’] in /code/at...
- Affected:
- up to 2.6
- Fixed in:
- 2.6
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database