My Private Site [jonradio-private-site] < 3.1.0
unknown
[en] The My Private Site plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.0.14 via the REST API. This makes it possible for unauthenticated attackers to bypass the plugin's site privacy feature and view restricted page and post content.
- Affected:
- up to 3.1.0
- Fixed in:
- 3.1.0
- Disclosed:
- Feb 20, 2024
CVE-2024-0978 on NVD →
My Private Site <= 3.0.14 - Improper Access Control to Sensitive Information Exposure via REST API
medium
The My Private Site plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.0.14 via the REST API. This makes it possible for unauthenticated attackers to bypass the plugin's site privacy feature and view restricted page and post content.
- CVSS:
- 5.3
- Affected:
- up to 3.0.14
- Fixed in:
- 3.1.0
- Disclosed:
- Feb 16, 2024
CVE-2024-0978 on NVD →
My Private Site [jonradio-private-site] < 3.0.8
unknown
[en] The My Private Site WordPress plugin before 3.0.8 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack
- Affected:
- up to 3.0.8
- Fixed in:
- 3.0.8
- Disclosed:
- Jun 27, 2022
CVE-2022-1627 on NVD →
My Private Site <= 3.0.7 - Cross-Site Request Forgery
high
The plugin My Private Site for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.0.7. This is due to missing or incorrect nonce validation in the my_private_site_tab_advanced_process_buttons function. This makes it possible for unauthenticated attackers to inject malicious JavaSc...
- CVSS:
- 8.8
- Affected:
- up to 3.0.7
- Fixed in:
- 3.0.8
- Disclosed:
- May 29, 2022
CVE-2022-1627 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database