LadiApp: Landing Page, PopupX, Marketing Automation, Affiliate Marketing… [ladipage] <= 4.4 (unfixed + closed)
unknown
[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in LadiPage LadiApp allows Stored XSS.This issue affects LadiApp: from n/a through 4.4.
- Affected:
- up to 4.4
- Fix:
- No patched version reported
- Disclosed:
- Dec 9, 2024
CVE-2023-49158 on NVD →
LadiApp: Landing Page, PopupX, Marketing Automation, Affiliate Marketing… [ladipage] <= 4.3 (unfixed + closed)
unknown
[en] The LadiApp plugn for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the init_endpoint() function hooked via 'init' in versions up to, and including, 4.3. This makes it possible for unauthenticated attackers to modify a variety of settings. An attacker can directl...
- Affected:
- up to 4.3
- Fix:
- No patched version reported
- Disclosed:
- Aug 17, 2024
CVE-2023-4730 on NVD →
LadiApp: Landing Page, PopupX, Marketing Automation, Affiliate Marketing… <= 4.3 - Missing Authorization via init_endpoint
medium
The LadiApp plugn for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the init_endpoint() function hooked via 'init' in versions up to, and including, 4.3. This makes it possible for unauthenticated attackers to modify a variety of settings. An attacker can directly mod...
- CVSS:
- 5.3
- Affected:
- up to 4.3
- Fix:
- No patched version reported
- Disclosed:
- Aug 16, 2024
CVE-2023-4730 on NVD →
LadiApp: Landing Page, PopupX, Marketing Automation, Affiliate Marketing… [ladipage] <= 4.4 (unfixed + closed)
unknown
[en] The LadiApp plugin for WordPress is vulnerable to Cross-Site Request Forgery due to a missing nonce check on the publish_lp() function hooked via an AJAX action in versions up to, and including, 4.4. This makes it possible for unauthenticated attackers to change the LadiPage key (a key fully controlled by the atta...
- Affected:
- up to 4.4
- Fix:
- No patched version reported
- Disclosed:
- Mar 12, 2024
CVE-2023-4729 on NVD →
LadiApp: Landing Page, PopupX, Marketing Automation, Affiliate Marketing… [ladipage] <= 4.4 (unfixed + closed)
unknown
[en] The LadiApp plugin for WordPress is vulnerable to Cross-Site Request Forgery due to a missing nonce check on the save_config() function in versions up to, and including, 4.3. This makes it possible for unauthenticated attackers to update the 'ladipage_config' option via a forged request granted they can trick a si...
- Affected:
- up to 4.4
- Fix:
- No patched version reported
- Disclosed:
- Mar 12, 2024
CVE-2023-4629 on NVD →
LadiApp: Landing Page, PopupX, Marketing Automation, Affiliate Marketing… [ladipage] <= 4.4 (unfixed + closed)
unknown
[en] The LadiApp plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the save_config() function in versions up to, and including, 4.4. This makes it possible for authenticated attackers with subscriber-level access and above to update the 'ladipage_config' option...
- Affected:
- up to 4.4
- Fix:
- No patched version reported
- Disclosed:
- Mar 12, 2024
CVE-2023-4627 on NVD →
LadiApp: Landing Page, PopupX, Marketing Automation, Affiliate Marketing… [ladipage] <= 4.4 (unfixed + closed)
unknown
[en] The LadiApp plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the publish_lp() function hooked via an AJAX action in versions up to, and including, 4.4. This makes it possible for authenticated attackers with subscriber-level access and above to change the...
- Affected:
- up to 4.4
- Fix:
- No patched version reported
- Disclosed:
- Mar 12, 2024
CVE-2023-4728 on NVD →
LadiApp: Landing Page, PopupX, Marketing Automation, Affiliate Marketing… [ladipage] <= 4.4 (unfixed + closed)
unknown
[en] The LadiApp plugin for WordPress is vulnerable to Cross-Site Request Forgery due to a missing nonce check on the ladiflow_save_hook() function in versions up to, and including, 4.4. This makes it possible for unauthenticated attackers to update the 'ladiflow_hook_configs' option via a forged request granted they c...
- Affected:
- up to 4.4
- Fix:
- No patched version reported
- Disclosed:
- Mar 12, 2024
CVE-2023-4628 on NVD →
LadiApp: Landing Page, PopupX, Marketing Automation, Affiliate Marketing… [ladipage] <= 4.4 (unfixed + closed)
unknown
[en] The LadiApp plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the ladiflow_save_hook() function in versions up to, and including, 4.3. This makes it possible for authenticated attackers with subscriber-level access and above to update the 'ladiflow_hook_co...
- Affected:
- up to 4.4
- Fix:
- No patched version reported
- Disclosed:
- Mar 12, 2024
CVE-2023-4626 on NVD →
LadiApp: Landing Page, PopupX, Marketing Automation, Affiliate Marketing… [ladipage] <= 4.4 (unfixed + closed)
unknown
[en] The LadiApp plugn for WordPress is vulnerable to Cross-Site Request Forgery due to a missing nonce check on the init_endpoint() function hooked via 'init' in versions up to, and including, 4.4. This makes it possible for unauthenticated attackers to modify a variety of settings, via a forged request granted they c...
- Affected:
- up to 4.4
- Fix:
- No patched version reported
- Disclosed:
- Mar 12, 2024
CVE-2023-4731 on NVD →
LadiApp <= 4.4 - Missing Authorization via ladiflow_save_hook()
medium
The LadiApp plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the ladiflow_save_hook() function in versions up to, and including, 4.3. This makes it possible for authenticated attackers with subscriber-level access and above to update the 'ladiflow_hook_configs...
- CVSS:
- 4.3
- Affected:
- 4.3 – 4.3
- Fix:
- No patched version reported
- Disclosed:
- Mar 11, 2024
CVE-2023-4626 on NVD →
LadiApp: Landing Page, PopupX, Marketing Automation, Affiliate Marketing… <= 4.4 - Missing Authorization on publish_lp()
medium
The LadiApp plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the publish_lp() function hooked via an AJAX action in versions up to, and including, 4.4. This makes it possible for authenticated attackers with subscriber-level access and above to change the Ladi...
- CVSS:
- 4.3
- Affected:
- up to 4.4
- Fix:
- No patched version reported
- Disclosed:
- Mar 11, 2024
CVE-2023-4728 on NVD →
LadiApp <= 4.4 - Missing Authorization via save_config()
medium
The LadiApp plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the save_config() function in versions up to, and including, 4.4. This makes it possible for authenticated attackers with subscriber-level access and above to update the 'ladipage_config' option.
- CVSS:
- 4.3
- Affected:
- up to 4.4
- Fix:
- No patched version reported
- Disclosed:
- Mar 11, 2024
CVE-2023-4627 on NVD →
LadiApp: Landing Page, PopupX, Marketing Automation, Affiliate Marketing… <= 4.4 - Cross-Site Request Forgery via publish_lp()
medium
The LadiApp plugin for WordPress is vulnerable to Cross-Site Request Forgery due to a missing nonce check on the publish_lp() function hooked via an AJAX action in versions up to, and including, 4.4. This makes it possible for unauthenticated attackers to change the LadiPage key (a key fully controlled by the attacker)...
- CVSS:
- 4.3
- Affected:
- up to 4.4
- Fix:
- No patched version reported
- Disclosed:
- Mar 11, 2024
CVE-2023-4729 on NVD →
LadiApp <= 4.4 - Cross-Site Request Forgery via save_config()
medium
The LadiApp plugin for WordPress is vulnerable to Cross-Site Request Forgery due to a missing nonce check on the save_config() function in versions up to, and including, 4.3. This makes it possible for unauthenticated attackers to update the 'ladipage_config' option via a forged request granted they can trick a site ad...
- CVSS:
- 4.3
- Affected:
- up to 4.3
- Fix:
- No patched version reported
- Disclosed:
- Mar 11, 2024
CVE-2023-4629 on NVD →
LadiApp: Landing Page, PopupX, Marketing Automation, Affiliate Marketing… <= 4.4 - Cross-Site Request Forgery via init_endpoint
medium
The LadiApp plugn for WordPress is vulnerable to Cross-Site Request Forgery due to a missing nonce check on the init_endpoint() function hooked via 'init' in versions up to, and including, 4.4. This makes it possible for unauthenticated attackers to modify a variety of settings, via a forged request granted they can tr...
- CVSS:
- 4.3
- Affected:
- up to 4.4
- Fix:
- No patched version reported
- Disclosed:
- Mar 11, 2024
CVE-2023-4731 on NVD →
LadiApp <= 4.4 - Cross-Site Request Forgery via ladiflow_save_hook()
medium
The LadiApp plugin for WordPress is vulnerable to Cross-Site Request Forgery due to a missing nonce check on the ladiflow_save_hook() function in versions up to, and including, 4.4. This makes it possible for unauthenticated attackers to update the 'ladiflow_hook_configs' option via a forged request granted they can tr...
- CVSS:
- 4.3
- Affected:
- up to 4.4
- Fix:
- No patched version reported
- Disclosed:
- Mar 11, 2024
CVE-2023-4628 on NVD →
LadiApp <= 4.3 - Missing Authorization
medium
The LadiApp plugin for WordPress is vulnerable to unauthorized access of data, modification of data, or loss of data due to a missing capability check on an unknown function in versions up to, and including, 4.3. This makes it possible for authenticated attackers, with subscriber-level access and above, to make use of...
- CVSS:
- 4.3
- Affected:
- up to 4.3
- Fix:
- No patched version reported
- Disclosed:
- Nov 28, 2023
CVE-2023-49158 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database