plugin

Igniteup Vulnerabilities

11 known security issues reported for the Igniteup WordPress plugin. Most recent disclosed May 9, 2022.

2 high 3 medium

Running Igniteup on your site? Check whether your installed version is affected.

Scan your site free

IgniteUp – Coming Soon and Maintenance Mode [igniteup] < 3.4.2 (closed)

unknown

[en] The IgniteUp WordPress plugin through 3.4.1 does not sanitise and escape some fields when high privilege users don't have the unfiltered_html capability, which could lead to Stored Cross-Site Scripting issues

Affected:
up to 3.4.2
Fixed in:
3.4.2
Disclosed:
May 9, 2022

CVE-2022-0898 on NVD →

IgniteUp – Coming Soon and Maintenance Mode <= 3.4.1 - Authenticated (Admin+) Stored Cross-Site Scripting

medium

The IgniteUp WordPress plugin through 3.4.1 does not sanitise and escape some fields when high privilege users don't have the unfiltered_html capability, which could lead to Stored Cross-Site Scripting issues

CVSS:
5.5
Affected:
up to 3.4.1
Fixed in:
3.4.2
Disclosed:
Apr 13, 2022

CVE-2022-0898 on NVD →

IgniteUp – Coming Soon and Maintenance Mode [igniteup] < 3.4.1

unknown

[en] includes/class-coming-soon-creator.php in the igniteup plugin through 3.4 for WordPress allows unauthenticated arbitrary file deletion.

Affected:
up to 3.4.1
Fixed in:
3.4.1
Disclosed:
Nov 12, 2019

CVE-2019-17234 on NVD →

IgniteUp – Coming Soon and Maintenance Mode [igniteup] < 3.4.1

unknown

[en] includes/class-coming-soon-creator.php in the igniteup plugin through 3.4 for WordPress allows information disclosure.

Affected:
up to 3.4.1
Fixed in:
3.4.1
Disclosed:
Nov 12, 2019

CVE-2019-17235 on NVD →

IgniteUp – Coming Soon and Maintenance Mode [igniteup] < 3.4.1 (closed)

unknown

[en] includes/class-coming-soon-creator.php in the igniteup plugin through 3.4 for WordPress is vulnerable to stored XSS.

Affected:
up to 3.4.1
Fixed in:
3.4.1
Disclosed:
Nov 12, 2019

CVE-2019-17236 on NVD →

IgniteUp – Coming Soon and Maintenance Mode [igniteup] < 3.4.1 (closed)

unknown

[en] includes/class-coming-soon-creator.php in the igniteup plugin through 3.4 for WordPress allows CSRF.

Affected:
up to 3.4.1
Fixed in:
3.4.1
Disclosed:
Nov 12, 2019

CVE-2019-17237 on NVD →

IgniteUp – Coming Soon and Maintenance Mode [igniteup] < 3.4.1 (unfixed + closed)

unknown

Multiple vulnerabilities found by Jerome Bruandet in WordPress IgniteUp plugin (versions <=3.4). Vulnerabilities that could be exploited by unauthenticated users include Arbitrary File Deletion, HTML injection & CSRF in email messages, Stored Cross-Site Scripting (XSS), Sensitive Information Disclosure, Arbitrary subsc...

Affected:
up to 3.4.1
Fix:
No patched version reported
Disclosed:
Nov 11, 2019

IgniteUp – Coming Soon and Maintenance Mode <= 3.4.0 - Cross-Site Request Forgery

high

includes/class-coming-soon-creator.php in the igniteup plugin through 3.4 for WordPress allows CSRF.

CVSS:
8.8
Affected:
up to 3.4.0
Fixed in:
3.4.1
Disclosed:
Nov 10, 2019

CVE-2019-17237 on NVD →

IgniteUp – Coming Soon and Maintenance Mode <= 3.4 - Unauthenticated Arbitrary File Deletion

high

includes/class-coming-soon-creator.php in the igniteup plugin through 3.4 for WordPress allows unauthenticated arbitrary file deletion.

CVSS:
7.5
Affected:
up to 3.4.1
Fixed in:
3.4.1
Disclosed:
Nov 10, 2019

CVE-2019-17234 on NVD →

IgniteUp – Coming Soon and Maintenance Mode <= 3.4 - Stored Cross-Site Scripting

medium

includes/class-coming-soon-creator.php in the igniteup plugin through 3.4 for WordPress is vulnerable to stored XSS.

CVSS:
6.1
Affected:
up to 3.4.1
Fixed in:
3.4.1
Disclosed:
Nov 10, 2019

CVE-2019-17236 on NVD →

IgniteUp – Coming Soon and Maintenance Mode <= 3.4.0 - Information Disclosure

medium

includes/class-coming-soon-creator.php in the igniteup plugin through 3.4 for WordPress allows information disclosure.

CVSS:
5.3
Affected:
up to 3.4.0
Fixed in:
3.4.1
Disclosed:
Nov 10, 2019

CVE-2019-17235 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database