plugin

Kd Coming Soon Vulnerabilities

2 known security issues reported for the Kd Coming Soon WordPress plugin. Most recent disclosed Feb 12, 2024.

1 high

Running Kd Coming Soon on your site? Check whether your installed version is affected.

Scan your site free

KD Coming Soon [kd-coming-soon] <= 1.7 (unfixed + closed)

unknown

[en] Deserialization of Untrusted Data vulnerability in Kalli Dan. KD Coming Soon.This issue affects KD Coming Soon: from n/a through 1.7.

Affected:
up to 1.7
Fix:
No patched version reported
Disclosed:
Feb 12, 2024

CVE-2023-46615 on NVD →

KD Coming Soon <= 1.7 - Unauthenticated PHP Object Injection via cetitle

high

The KD Coming Soon plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.7 via deserialization of untrusted input cetitle in the vulnerable kd_cemailer function. This makes it possible for unauthenticated attackers to inject a PHP Object. No POP chain is present in the vulne...

CVSS:
8.1
Affected:
up to 1.7
Fix:
No patched version reported
Disclosed:
Oct 24, 2023

CVE-2023-46615 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database