Hermit 音乐播放器 <= 3.1.6 - Multiple Cross-Site Request Forgery
medium
Hermit 音乐播放器 <= 3.1.6 is vulnerable to Cross-Site Request Forgery. This allow attackers to delete cache, delete a source, create source.
- CVSS:
- 5.4
- Affected:
- up to 3.1.6
- Fix:
- No patched version reported
- Disclosed:
- Apr 28, 2022
CVE-2022-29412 on NVD →
Hermit 音乐播放器 <= 3.1.6 - Cross-Site Request Forgery to Stored Cross-Site Scripting
high
Cross-Site Request Forgery (CSRF) leading to Stored Cross-Site Scripting (XSS) in Mufeng's Hermit 音乐播放器 plugin <= 3.1.6 on WordPress via title parameter.
- CVSS:
- 8.8
- Affected:
- up to 3.1.6
- Fix:
- No patched version reported
- Disclosed:
- Apr 28, 2022
CVE-2022-29413 on NVD →
Hermit 音乐播放器 <= 3.1.6 - Unauthenticated SQL Injection
critical
Mufeng's Hermit 音乐播放器 plugin <= 3.1.6 is vulnerable to SQL injection. This allows unauthenticated attackers to execute SQLi attack via (&id). Versions up to 3.1.6 are affected.
- CVSS:
- 9.8
- Affected:
- up to 3.1.6
- Fix:
- No patched version reported
- Disclosed:
- Apr 28, 2022
CVE-2022-29411 on NVD →
Hermit 音乐播放器 <= 3.1.6 - Authenticated (Subscriber+) SQL Injection
high
Mufeng's Hermit 音乐播放器 plugin <= 3.1.6 is vulnerable to SQL injection. This allows authenticated attackers with Subscriber or higher user roles to execute SQLi attack via (&ids). Versions up to 3.1.6 are affected.
- CVSS:
- 8.8
- Affected:
- up to 3.1.6
- Fix:
- No patched version reported
- Disclosed:
- Apr 28, 2022
CVE-2022-29410 on NVD →
Hermit 音乐播放器 [hermit] <= 3.1.6 (closed)
unknown
[en] SQL Injection (SQLi) vulnerability in Mufeng's Hermit 音乐播放器 plugin <= 3.1.6 on WordPress allows attackers to execute SQLi attack via (&id).
- Affected:
- up to 3.1.6
- Fixed in:
- 3.1.6
- Disclosed:
- Apr 28, 2022
CVE-2022-29411 on NVD →
Hermit 音乐播放器 [hermit] <= 3.1.6 (closed)
unknown
[en] Authenticated SQL Injection (SQLi) vulnerability in Mufeng's Hermit 音乐播放器 plugin <= 3.1.6 on WordPress allows attackers with Subscriber or higher user roles to execute SQLi attack via (&ids).
- Affected:
- up to 3.1.6
- Fixed in:
- 3.1.6
- Disclosed:
- Apr 28, 2022
CVE-2022-29410 on NVD →
Hermit 音乐播放器 [hermit] <= 3.1.6 (closed)
unknown
[en] Multiple Cross-Site Request Forgery (CSRF) vulnerabilities in Hermit 音乐播放器 plugin <= 3.1.6 on WordPress allow attackers to delete cache, delete a source, create source.
- Affected:
- up to 3.1.6
- Fixed in:
- 3.1.6
- Disclosed:
- Apr 28, 2022
CVE-2022-29412 on NVD →
Hermit 音乐播放器 [hermit] <= 3.1.6 (closed)
unknown
[en] Cross-Site Request Forgery (CSRF) leading to Stored Cross-Site Scripting (XSS) in Mufeng's Hermit 音乐播放器 plugin <= 3.1.6 on WordPress via &title parameter.
- Affected:
- up to 3.1.6
- Fixed in:
- 3.1.6
- Disclosed:
- Apr 28, 2022
CVE-2022-29413 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database