IgniteUp – Coming Soon and Maintenance Mode [igniteup] < 3.4.2 (closed)
unknown
[en] The IgniteUp WordPress plugin through 3.4.1 does not sanitise and escape some fields when high privilege users don't have the unfiltered_html capability, which could lead to Stored Cross-Site Scripting issues
- Affected:
- up to 3.4.2
- Fixed in:
- 3.4.2
- Disclosed:
- May 9, 2022
CVE-2022-0898 on NVD →
IgniteUp – Coming Soon and Maintenance Mode <= 3.4.1 - Authenticated (Admin+) Stored Cross-Site Scripting
medium
The IgniteUp WordPress plugin through 3.4.1 does not sanitise and escape some fields when high privilege users don't have the unfiltered_html capability, which could lead to Stored Cross-Site Scripting issues
- CVSS:
- 5.5
- Affected:
- up to 3.4.1
- Fixed in:
- 3.4.2
- Disclosed:
- Apr 13, 2022
CVE-2022-0898 on NVD →
IgniteUp – Coming Soon and Maintenance Mode [igniteup] < 3.4.1
unknown
[en] includes/class-coming-soon-creator.php in the igniteup plugin through 3.4 for WordPress allows unauthenticated arbitrary file deletion.
- Affected:
- up to 3.4.1
- Fixed in:
- 3.4.1
- Disclosed:
- Nov 12, 2019
CVE-2019-17234 on NVD →
IgniteUp – Coming Soon and Maintenance Mode [igniteup] < 3.4.1
unknown
[en] includes/class-coming-soon-creator.php in the igniteup plugin through 3.4 for WordPress allows information disclosure.
- Affected:
- up to 3.4.1
- Fixed in:
- 3.4.1
- Disclosed:
- Nov 12, 2019
CVE-2019-17235 on NVD →
IgniteUp – Coming Soon and Maintenance Mode [igniteup] < 3.4.1 (closed)
unknown
[en] includes/class-coming-soon-creator.php in the igniteup plugin through 3.4 for WordPress is vulnerable to stored XSS.
- Affected:
- up to 3.4.1
- Fixed in:
- 3.4.1
- Disclosed:
- Nov 12, 2019
CVE-2019-17236 on NVD →
IgniteUp – Coming Soon and Maintenance Mode [igniteup] < 3.4.1 (closed)
unknown
[en] includes/class-coming-soon-creator.php in the igniteup plugin through 3.4 for WordPress allows CSRF.
- Affected:
- up to 3.4.1
- Fixed in:
- 3.4.1
- Disclosed:
- Nov 12, 2019
CVE-2019-17237 on NVD →
IgniteUp – Coming Soon and Maintenance Mode [igniteup] < 3.4.1 (unfixed + closed)
unknown
Multiple vulnerabilities found by Jerome Bruandet in WordPress IgniteUp plugin (versions <=3.4). Vulnerabilities that could be exploited by unauthenticated users include Arbitrary File Deletion, HTML injection & CSRF in email messages, Stored Cross-Site Scripting (XSS), Sensitive Information Disclosure, Arbitrary subsc...
- Affected:
- up to 3.4.1
- Fix:
- No patched version reported
- Disclosed:
- Nov 11, 2019
IgniteUp – Coming Soon and Maintenance Mode <= 3.4.0 - Cross-Site Request Forgery
high
includes/class-coming-soon-creator.php in the igniteup plugin through 3.4 for WordPress allows CSRF.
- CVSS:
- 8.8
- Affected:
- up to 3.4.0
- Fixed in:
- 3.4.1
- Disclosed:
- Nov 10, 2019
CVE-2019-17237 on NVD →
IgniteUp – Coming Soon and Maintenance Mode <= 3.4 - Unauthenticated Arbitrary File Deletion
high
includes/class-coming-soon-creator.php in the igniteup plugin through 3.4 for WordPress allows unauthenticated arbitrary file deletion.
- CVSS:
- 7.5
- Affected:
- up to 3.4.1
- Fixed in:
- 3.4.1
- Disclosed:
- Nov 10, 2019
CVE-2019-17234 on NVD →
IgniteUp – Coming Soon and Maintenance Mode <= 3.4 - Stored Cross-Site Scripting
medium
includes/class-coming-soon-creator.php in the igniteup plugin through 3.4 for WordPress is vulnerable to stored XSS.
- CVSS:
- 6.1
- Affected:
- up to 3.4.1
- Fixed in:
- 3.4.1
- Disclosed:
- Nov 10, 2019
CVE-2019-17236 on NVD →
IgniteUp – Coming Soon and Maintenance Mode <= 3.4.0 - Information Disclosure
medium
includes/class-coming-soon-creator.php in the igniteup plugin through 3.4 for WordPress allows information disclosure.
- CVSS:
- 5.3
- Affected:
- up to 3.4.0
- Fixed in:
- 3.4.1
- Disclosed:
- Nov 10, 2019
CVE-2019-17235 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database