plugin

Invite Anyone Vulnerabilities

15 known security issues reported for the Invite Anyone WordPress plugin. Most recent disclosed Aug 18, 2024.

1 critical 3 high 2 medium

Running Invite Anyone on your site? Check whether your installed version is affected.

Scan your site free

Invite Anyone [invite-anyone] < 1.4.8

unknown

[en] Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Boone Gorges Invite Anyone allows Reflected XSS.This issue affects Invite Anyone: from n/a through 1.4.7.

Affected:
up to 1.4.8
Fixed in:
1.4.8
Disclosed:
Aug 18, 2024

CVE-2024-43327 on NVD →

Invite Anyone <= 1.4.7 - Reflected Cross-Site Scripting

medium

The Invite Anyone plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 1.4.7 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully t...

CVSS:
6.1
Affected:
up to 1.4.7
Fixed in:
1.4.8
Disclosed:
Aug 16, 2024

CVE-2024-43327 on NVD →

Invite Anyone [invite-anyone] < 1.3.16

unknown

[en] The invite-anyone plugin before 1.3.16 for WordPress has incorrect access control for email-based invitations.

Affected:
up to 1.3.16
Fixed in:
1.3.16
Disclosed:
Aug 16, 2019

CVE-2017-18543 on NVD →

Invite Anyone [invite-anyone] < 1.3.16

unknown

[en] The invite-anyone plugin before 1.3.16 for WordPress has incorrect escaping of untrusted Dashboard and front-end input.

Affected:
up to 1.3.16
Fixed in:
1.3.16
Disclosed:
Aug 16, 2019

CVE-2017-18545 on NVD →

Invite Anyone [invite-anyone] < 1.3.16

unknown

[en] The invite-anyone plugin before 1.3.16 for WordPress has admin-panel CSRF.

Affected:
up to 1.3.16
Fixed in:
1.3.16
Disclosed:
Aug 16, 2019

CVE-2017-18544 on NVD →

Invite Anyone [invite-anyone] < 1.3.19

unknown

Unauthenticated PHP Object Injection vulnerability found in WordPress Invite Anyone plugin (versions <=1.3.18).

Affected:
up to 1.3.19
Fixed in:
1.3.19
Disclosed:
Oct 13, 2017

Invite Anyone <= 1.3.18 - PHP Object Injection

critical

The Invite Anyone plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 1.3.18 via deserialization of untrusted input from the 'invite-anyone/trunk/by-email/by-email.php' file. This allows unauthenticated attackers to inject a PHP Object.

CVSS:
9.8
Affected:
up to 1.3.18
Fixed in:
1.3.19
Disclosed:
Oct 12, 2017

Invite Anyone [invite-anyone] < 1.3.19

unknown

The Invite Anyone plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 1.3.18 via deserialization of untrusted input from the 'invite-anyone/trunk/by-email/by-email.php' file. This allows unauthenticated attackers to inject a PHP Object.

Affected:
up to 1.3.19
Fixed in:
1.3.19
Disclosed:
Oct 12, 2017

Invite Anyone < 1.3.16 - Cross-Site Request Forgery

high

The Invite Anyone plugin before 1.3.16 for WordPress has admin-panel CSRF. The plugin’s setting pages had a vulnerability found in the nonce, which is used to prevent CSRF, but when the settings are saved there was no check to a validate if a nonce was included.

CVSS:
8.8
Affected:
up to 1.3.16
Fixed in:
1.3.16
Disclosed:
Mar 22, 2017

CVE-2017-18544 on NVD →

Invite Anyone <= 1.3.15 - Improper Input Validation

high

The invite-anyone plugin before 1.3.16 for WordPress has incorrect escaping of untrusted Dashboard and front-end input.

CVSS:
7.5
Affected:
up to 1.3.15
Fixed in:
1.3.16
Disclosed:
Mar 22, 2017

CVE-2017-18545 on NVD →

Invite Anyone < 1.3.16 - Email Injection

high

The Invite Anyone plugin before 1.3.16 for WordPress has incorrect access control for email-based invitations.

CVSS:
7.5
Affected:
up to 1.3.16
Fixed in:
1.3.16
Disclosed:
Mar 22, 2017

CVE-2017-18543 on NVD →

Invite Anyone [invite-anyone] < 1.3.16

unknown

WordPress Invite Anyone plugin Cross-Site Request Forgery (CSRF) and Cross-Site Scripting (XSS) vulnerabilities were found in 1.3.15 version. The settings are passed without any sanitization to function register_setting(). Update the plugin.

Affected:
up to 1.3.16
Fixed in:
1.3.16
Disclosed:
Mar 22, 2017

Invite Anyone <= 1.3.14 - Change of Email Invitation Content

medium

An issue was discovered in by-email/by-email.php in the Invite Anyone plugin before 1.3.15 for WordPress. A user is able to change the subject and the body of the invitation mail that should be immutable, which facilitates a social engineering attack.

CVSS:
5.3
Affected:
up to 1.3.15
Fixed in:
1.3.15
Disclosed:
Mar 17, 2017

CVE-2017-6955 on NVD →

Invite Anyone [invite-anyone] < 1.3.15

unknown

[en] An issue was discovered in by-email/by-email.php in the Invite Anyone plugin before 1.3.15 for WordPress. A user is able to change the subject and the body of the invitation mail that should be immutable, which facilitates a social engineering attack.

Affected:
up to 1.3.15
Fixed in:
1.3.15
Disclosed:
Mar 17, 2017

CVE-2017-6955 on NVD →

Invite Anyone [invite-anyone] < 1.3.19

unknown

The plugin invite-anyone insecurely trusts serialized data submitted over HTTP requests. This opens up the site to a PHP object injection vulnerability potential exploit vector.

Affected:
up to 1.3.19
Fixed in:
1.3.19

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database