Dynamics 365 Integration [integration-dynamics] < 1.3.24
unknown
[en] The Dynamics 365 Integration plugin for WordPress is vulnerable to Remote Code Execution and Arbitrary File Read in all versions up to, and including, 1.3.23 via Twig Server-Side Template Injection. This is due to missing input validation and sanitization on the render function. This makes it possible for authenti...
- Affected:
- up to 1.3.24
- Fixed in:
- 1.3.24
- Disclosed:
- Jan 4, 2025
CVE-2024-12583 on NVD →
Dynamics 365 Integration <= 1.3.23 - Authenticated (Contributor+) Remote Code Execution and Arbitrary File Read via Twig Server-Side Template Injection
critical
The Dynamics 365 Integration plugin for WordPress is vulnerable to Remote Code Execution and Arbitrary File Read in all versions up to, and including, 1.3.23 via Twig Server-Side Template Injection. This is due to missing input validation and sanitization on the render function. This makes it possible for authenticated...
- CVSS:
- 9.9
- Affected:
- up to 1.3.23
- Fixed in:
- 1.3.24
- Disclosed:
- Jan 3, 2025
CVE-2024-12583 on NVD →
Dynamics 365 Integration [integration-dynamics] < 1.3.13
unknown
[en] Missing Authorization vulnerability in AlexaCRM Dynamics 365 Integration allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Dynamics 365 Integration: from n/a through 1.3.12.
- Affected:
- up to 1.3.13
- Fixed in:
- 1.3.13
- Disclosed:
- Dec 9, 2024
CVE-2023-28417 on NVD →
Dynamics 365 Integration [integration-dynamics] < 1.3.14
unknown
[en] Missing Authorization vulnerability in AlexaCRM Dynamics 365 Integration allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Dynamics 365 Integration: from n/a through 1.3.13.
- Affected:
- up to 1.3.14
- Fixed in:
- 1.3.14
- Disclosed:
- Dec 9, 2024
CVE-2023-29422 on NVD →
Dynamics 365 Integration [integration-dynamics] < 1.3.18
unknown
[en] Insertion of Sensitive Information into Log File vulnerability in AlexaCRM Dynamics 365 Integration.This issue affects Dynamics 365 Integration: from n/a through 1.3.17.
- Affected:
- up to 1.3.18
- Fixed in:
- 1.3.18
- Disclosed:
- May 9, 2024
CVE-2024-34550 on NVD →
Dynamics 365 Integration <= 1.3.17 - Unauthenticated Sensitive Information Exposure
medium
The Dynamics 365 Integration plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.3.17 through publicly exposed log files. This makes it possible for unauthenticated attackers to view potentially sensitive information contained in the exposed log files.
- CVSS:
- 5.3
- Affected:
- up to 1.3.17
- Fixed in:
- 1.3.18
- Disclosed:
- May 7, 2024
CVE-2024-34550 on NVD →
Dynamics 365 Integration <= 1.3.13 - Missing Authorization via init
medium
The Dynamics 365 Integration plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the init function in versions up to, and including, 1.3.13. This makes it possible for authenticated attackers , with subscriber-level access and above, to trigger the clear cache fe...
- CVSS:
- 4.3
- Affected:
- up to 1.3.13
- Fixed in:
- 1.3.14
- Disclosed:
- Apr 6, 2023
CVE-2023-29422 on NVD →
Dynamics 365 Integration <= 1.3.12 - Missing Authorization via wp_ajax_wpcrm_log & wp_ajax_wpcrm_log_verbosity
medium
The Dynamics 365 Integration plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the wp_ajax_wpcrm_log & wp_ajax_wpcrm_log_verbosity functions in versions up to, and including, 1.3.12. This makes it possible for authenticated attackers with subscriber-level acces...
- CVSS:
- 5.4
- Affected:
- up to 1.3.12
- Fixed in:
- 1.3.13
- Disclosed:
- Mar 15, 2023
CVE-2023-28417 on NVD →
Dynamics 365 Integration <= 1.3.12 - Cross-Site Request Forgery via wp_ajax_wpcrm_log_verbosity
medium
The Dynamics 365 Integration plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.3.12. This is due to missing or incorrect nonce validation on 'wp_ajax_wpcrm_log_verbosity' AJAX action. This makes it possible for unauthenticated attackers to change the log verbosity via...
- CVSS:
- 4.3
- Affected:
- up to 1.3.12
- Fixed in:
- 1.3.13
- Disclosed:
- Mar 14, 2023
Dynamics 365 Integration [integration-dynamics] < 1.3.13
unknown
The Dynamics 365 Integration plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.3.12. This is due to missing or incorrect nonce validation on 'wp_ajax_wpcrm_log_verbosity' AJAX action. This makes it possible for unauthenticated attackers to change the log verbosity via...
- Affected:
- up to 1.3.13
- Fixed in:
- 1.3.13
- Disclosed:
- Mar 14, 2023
Dynamics 365 Integration <= 1.3.12 - Cross-Site Request Forgery via wp_ajax_wpcrm_log
medium
The Dynamics 365 Integration plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.3.12. This is due to missing or incorrect nonce validation on 'wp_ajax_wpcrm_log' AJAX action. This makes it possible for unauthenticated attackers to trigger the download of log files via a...
- CVSS:
- 4.3
- Affected:
- up to 1.3.12
- Fixed in:
- 1.3.13
- Disclosed:
- Mar 13, 2023
Dynamics 365 Integration [integration-dynamics] < 1.3.13
unknown
The Dynamics 365 Integration plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.3.12. This is due to missing or incorrect nonce validation on 'wp_ajax_wpcrm_log' AJAX action. This makes it possible for unauthenticated attackers to trigger the download of log files via a...
- Affected:
- up to 1.3.13
- Fixed in:
- 1.3.13
- Disclosed:
- Mar 13, 2023
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database