plugin

Hl Twitter Vulnerabilities

6 known security issues reported for the Hl Twitter WordPress plugin. Most recent disclosed May 15, 2024.

3 medium

Running Hl Twitter on your site? Check whether your installed version is affected.

Scan your site free

HL Twitter [hl-twitter] <= 2014.1.18 (unfixed + closed)

unknown

[en] The HL Twitter WordPress plugin through 2014.1.18 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack

Affected:
up to 2014.1.18
Fix:
No patched version reported
Disclosed:
May 15, 2024

CVE-2024-3629 on NVD →

HL Twitter [hl-twitter] <= 2014.1.18 (unfixed + closed)

unknown

[en] The HL Twitter WordPress plugin through 2014.1.18 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

Affected:
up to 2014.1.18
Fix:
No patched version reported
Disclosed:
May 15, 2024

CVE-2024-3630 on NVD →

HL Twitter [hl-twitter] <= 2014.1.18 (unfixed + closed)

unknown

[en] The HL Twitter WordPress plugin through 2014.1.18 does not have CSRF check when unlinking twitter accounts, which could allow attackers to make logged in admins perform such actions via a CSRF attack

Affected:
up to 2014.1.18
Fix:
No patched version reported
Disclosed:
May 15, 2024

CVE-2024-3631 on NVD →

HL Twitter <= 2014.1.18 - Authenticated (Admin+) Stored Cross-Site Scripting

medium

The HL Twitter plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 2014.1.18 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject ar...

CVSS:
4.4
Affected:
up to 2014.1.18
Fix:
No patched version reported
Disclosed:
Apr 24, 2024

CVE-2024-3630 on NVD →

HL Twitter <= 2014.1.18 - Cross-Site Request Forgery to Settings Update

medium

The HL Twitter plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2014.1.18. This is due to missing or incorrect nonce validation on the hl_twitter_settings page. This makes it possible for unauthenticated attackers to update the plugin's settings via a forged request...

CVSS:
4.3
Affected:
up to 2014.1.18
Fix:
No patched version reported
Disclosed:
Apr 24, 2024

CVE-2024-3629 on NVD →

HL Twitter <= 2014.1.18 - Cross-Site Request Forgery to Twitter Account Unlink

medium

The HL Twitter plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2014.1.18. This is due to missing or incorrect nonce validation on the hl_twitter_settings page. This makes it possible for unauthenticated attackers to unlink a Twitter account via a forged request gra...

CVSS:
4.3
Affected:
up to 2014.1.18
Fix:
No patched version reported
Disclosed:
Apr 24, 2024

CVE-2024-3631 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database