plugin

Integration Dynamics Vulnerabilities

12 known security issues reported for the Integration Dynamics WordPress plugin. Most recent disclosed Jan 4, 2025.

1 critical 5 medium

Running Integration Dynamics on your site? Check whether your installed version is affected.

Scan your site free

Dynamics 365 Integration [integration-dynamics] < 1.3.24

unknown

[en] The Dynamics 365 Integration plugin for WordPress is vulnerable to Remote Code Execution and Arbitrary File Read in all versions up to, and including, 1.3.23 via Twig Server-Side Template Injection. This is due to missing input validation and sanitization on the render function. This makes it possible for authenti...

Affected:
up to 1.3.24
Fixed in:
1.3.24
Disclosed:
Jan 4, 2025

CVE-2024-12583 on NVD →

Dynamics 365 Integration <= 1.3.23 - Authenticated (Contributor+) Remote Code Execution and Arbitrary File Read via Twig Server-Side Template Injection

critical

The Dynamics 365 Integration plugin for WordPress is vulnerable to Remote Code Execution and Arbitrary File Read in all versions up to, and including, 1.3.23 via Twig Server-Side Template Injection. This is due to missing input validation and sanitization on the render function. This makes it possible for authenticated...

CVSS:
9.9
Affected:
up to 1.3.23
Fixed in:
1.3.24
Disclosed:
Jan 3, 2025

CVE-2024-12583 on NVD →

Dynamics 365 Integration [integration-dynamics] < 1.3.13

unknown

[en] Missing Authorization vulnerability in AlexaCRM Dynamics 365 Integration allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Dynamics 365 Integration: from n/a through 1.3.12.

Affected:
up to 1.3.13
Fixed in:
1.3.13
Disclosed:
Dec 9, 2024

CVE-2023-28417 on NVD →

Dynamics 365 Integration [integration-dynamics] < 1.3.14

unknown

[en] Missing Authorization vulnerability in AlexaCRM Dynamics 365 Integration allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Dynamics 365 Integration: from n/a through 1.3.13.

Affected:
up to 1.3.14
Fixed in:
1.3.14
Disclosed:
Dec 9, 2024

CVE-2023-29422 on NVD →

Dynamics 365 Integration [integration-dynamics] < 1.3.18

unknown

[en] Insertion of Sensitive Information into Log File vulnerability in AlexaCRM Dynamics 365 Integration.This issue affects Dynamics 365 Integration: from n/a through 1.3.17.

Affected:
up to 1.3.18
Fixed in:
1.3.18
Disclosed:
May 9, 2024

CVE-2024-34550 on NVD →

Dynamics 365 Integration <= 1.3.17 - Unauthenticated Sensitive Information Exposure

medium

The Dynamics 365 Integration plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.3.17 through publicly exposed log files. This makes it possible for unauthenticated attackers to view potentially sensitive information contained in the exposed log files.

CVSS:
5.3
Affected:
up to 1.3.17
Fixed in:
1.3.18
Disclosed:
May 7, 2024

CVE-2024-34550 on NVD →

Dynamics 365 Integration <= 1.3.13 - Missing Authorization via init

medium

The Dynamics 365 Integration plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the init function in versions up to, and including, 1.3.13. This makes it possible for authenticated attackers , with subscriber-level access and above, to trigger the clear cache fe...

CVSS:
4.3
Affected:
up to 1.3.13
Fixed in:
1.3.14
Disclosed:
Apr 6, 2023

CVE-2023-29422 on NVD →

Dynamics 365 Integration <= 1.3.12 - Missing Authorization via wp_ajax_wpcrm_log & wp_ajax_wpcrm_log_verbosity

medium

The Dynamics 365 Integration plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the wp_ajax_wpcrm_log & wp_ajax_wpcrm_log_verbosity functions in versions up to, and including, 1.3.12. This makes it possible for authenticated attackers with subscriber-level acces...

CVSS:
5.4
Affected:
up to 1.3.12
Fixed in:
1.3.13
Disclosed:
Mar 15, 2023

CVE-2023-28417 on NVD →

Dynamics 365 Integration <= 1.3.12 - Cross-Site Request Forgery via wp_ajax_wpcrm_log_verbosity

medium

The Dynamics 365 Integration plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.3.12. This is due to missing or incorrect nonce validation on 'wp_ajax_wpcrm_log_verbosity' AJAX action. This makes it possible for unauthenticated attackers to change the log verbosity via...

CVSS:
4.3
Affected:
up to 1.3.12
Fixed in:
1.3.13
Disclosed:
Mar 14, 2023

Dynamics 365 Integration [integration-dynamics] < 1.3.13

unknown

The Dynamics 365 Integration plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.3.12. This is due to missing or incorrect nonce validation on 'wp_ajax_wpcrm_log_verbosity' AJAX action. This makes it possible for unauthenticated attackers to change the log verbosity via...

Affected:
up to 1.3.13
Fixed in:
1.3.13
Disclosed:
Mar 14, 2023

Dynamics 365 Integration <= 1.3.12 - Cross-Site Request Forgery via wp_ajax_wpcrm_log

medium

The Dynamics 365 Integration plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.3.12. This is due to missing or incorrect nonce validation on 'wp_ajax_wpcrm_log' AJAX action. This makes it possible for unauthenticated attackers to trigger the download of log files via a...

CVSS:
4.3
Affected:
up to 1.3.12
Fixed in:
1.3.13
Disclosed:
Mar 13, 2023

Dynamics 365 Integration [integration-dynamics] < 1.3.13

unknown

The Dynamics 365 Integration plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.3.12. This is due to missing or incorrect nonce validation on 'wp_ajax_wpcrm_log' AJAX action. This makes it possible for unauthenticated attackers to trigger the download of log files via a...

Affected:
up to 1.3.13
Fixed in:
1.3.13
Disclosed:
Mar 13, 2023

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database