plugin

Ladipage Vulnerabilities

18 known security issues reported for the Ladipage WordPress plugin. Most recent disclosed Dec 9, 2024.

9 medium

Running Ladipage on your site? Check whether your installed version is affected.

Scan your site free

LadiApp: Landing Page, PopupX, Marketing Automation, Affiliate Marketing&#8230; [ladipage] <= 4.4 (unfixed + closed)

unknown

[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in LadiPage LadiApp allows Stored XSS.This issue affects LadiApp: from n/a through 4.4.

Affected:
up to 4.4
Fix:
No patched version reported
Disclosed:
Dec 9, 2024

CVE-2023-49158 on NVD →

LadiApp: Landing Page, PopupX, Marketing Automation, Affiliate Marketing&#8230; [ladipage] <= 4.3 (unfixed + closed)

unknown

[en] The LadiApp plugn for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the init_endpoint() function hooked via 'init' in versions up to, and including, 4.3. This makes it possible for unauthenticated attackers to modify a variety of settings. An attacker can directl...

Affected:
up to 4.3
Fix:
No patched version reported
Disclosed:
Aug 17, 2024

CVE-2023-4730 on NVD →

LadiApp: Landing Page, PopupX, Marketing Automation, Affiliate Marketing… <= 4.3 - Missing Authorization via init_endpoint

medium

The LadiApp plugn for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the init_endpoint() function hooked via 'init' in versions up to, and including, 4.3. This makes it possible for unauthenticated attackers to modify a variety of settings. An attacker can directly mod...

CVSS:
5.3
Affected:
up to 4.3
Fix:
No patched version reported
Disclosed:
Aug 16, 2024

CVE-2023-4730 on NVD →

LadiApp: Landing Page, PopupX, Marketing Automation, Affiliate Marketing&#8230; [ladipage] <= 4.4 (unfixed + closed)

unknown

[en] The LadiApp plugin for WordPress is vulnerable to Cross-Site Request Forgery due to a missing nonce check on the publish_lp() function hooked via an AJAX action in versions up to, and including, 4.4. This makes it possible for unauthenticated attackers to change the LadiPage key (a key fully controlled by the atta...

Affected:
up to 4.4
Fix:
No patched version reported
Disclosed:
Mar 12, 2024

CVE-2023-4729 on NVD →

LadiApp: Landing Page, PopupX, Marketing Automation, Affiliate Marketing&#8230; [ladipage] <= 4.4 (unfixed + closed)

unknown

[en] The LadiApp plugin for WordPress is vulnerable to Cross-Site Request Forgery due to a missing nonce check on the save_config() function in versions up to, and including, 4.3. This makes it possible for unauthenticated attackers to update the 'ladipage_config' option via a forged request granted they can trick a si...

Affected:
up to 4.4
Fix:
No patched version reported
Disclosed:
Mar 12, 2024

CVE-2023-4629 on NVD →

LadiApp: Landing Page, PopupX, Marketing Automation, Affiliate Marketing&#8230; [ladipage] <= 4.4 (unfixed + closed)

unknown

[en] The LadiApp plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the save_config() function in versions up to, and including, 4.4. This makes it possible for authenticated attackers with subscriber-level access and above to update the 'ladipage_config' option...

Affected:
up to 4.4
Fix:
No patched version reported
Disclosed:
Mar 12, 2024

CVE-2023-4627 on NVD →

LadiApp: Landing Page, PopupX, Marketing Automation, Affiliate Marketing&#8230; [ladipage] <= 4.4 (unfixed + closed)

unknown

[en] The LadiApp plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the publish_lp() function hooked via an AJAX action in versions up to, and including, 4.4. This makes it possible for authenticated attackers with subscriber-level access and above to change the...

Affected:
up to 4.4
Fix:
No patched version reported
Disclosed:
Mar 12, 2024

CVE-2023-4728 on NVD →

LadiApp: Landing Page, PopupX, Marketing Automation, Affiliate Marketing&#8230; [ladipage] <= 4.4 (unfixed + closed)

unknown

[en] The LadiApp plugin for WordPress is vulnerable to Cross-Site Request Forgery due to a missing nonce check on the ladiflow_save_hook() function in versions up to, and including, 4.4. This makes it possible for unauthenticated attackers to update the 'ladiflow_hook_configs' option via a forged request granted they c...

Affected:
up to 4.4
Fix:
No patched version reported
Disclosed:
Mar 12, 2024

CVE-2023-4628 on NVD →

LadiApp: Landing Page, PopupX, Marketing Automation, Affiliate Marketing&#8230; [ladipage] <= 4.4 (unfixed + closed)

unknown

[en] The LadiApp plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the ladiflow_save_hook() function in versions up to, and including, 4.3. This makes it possible for authenticated attackers with subscriber-level access and above to update the 'ladiflow_hook_co...

Affected:
up to 4.4
Fix:
No patched version reported
Disclosed:
Mar 12, 2024

CVE-2023-4626 on NVD →

LadiApp: Landing Page, PopupX, Marketing Automation, Affiliate Marketing&#8230; [ladipage] <= 4.4 (unfixed + closed)

unknown

[en] The LadiApp plugn for WordPress is vulnerable to Cross-Site Request Forgery due to a missing nonce check on the init_endpoint() function hooked via 'init' in versions up to, and including, 4.4. This makes it possible for unauthenticated attackers to modify a variety of settings, via a forged request granted they c...

Affected:
up to 4.4
Fix:
No patched version reported
Disclosed:
Mar 12, 2024

CVE-2023-4731 on NVD →

LadiApp <= 4.4 - Missing Authorization via ladiflow_save_hook()

medium

The LadiApp plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the ladiflow_save_hook() function in versions up to, and including, 4.3. This makes it possible for authenticated attackers with subscriber-level access and above to update the 'ladiflow_hook_configs...

CVSS:
4.3
Affected:
4.3 – 4.3
Fix:
No patched version reported
Disclosed:
Mar 11, 2024

CVE-2023-4626 on NVD →

LadiApp: Landing Page, PopupX, Marketing Automation, Affiliate Marketing… <= 4.4 - Missing Authorization on publish_lp()

medium

The LadiApp plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the publish_lp() function hooked via an AJAX action in versions up to, and including, 4.4. This makes it possible for authenticated attackers with subscriber-level access and above to change the Ladi...

CVSS:
4.3
Affected:
up to 4.4
Fix:
No patched version reported
Disclosed:
Mar 11, 2024

CVE-2023-4728 on NVD →

LadiApp <= 4.4 - Missing Authorization via save_config()

medium

The LadiApp plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the save_config() function in versions up to, and including, 4.4. This makes it possible for authenticated attackers with subscriber-level access and above to update the 'ladipage_config' option.

CVSS:
4.3
Affected:
up to 4.4
Fix:
No patched version reported
Disclosed:
Mar 11, 2024

CVE-2023-4627 on NVD →

LadiApp: Landing Page, PopupX, Marketing Automation, Affiliate Marketing… <= 4.4 - Cross-Site Request Forgery via publish_lp()

medium

The LadiApp plugin for WordPress is vulnerable to Cross-Site Request Forgery due to a missing nonce check on the publish_lp() function hooked via an AJAX action in versions up to, and including, 4.4. This makes it possible for unauthenticated attackers to change the LadiPage key (a key fully controlled by the attacker)...

CVSS:
4.3
Affected:
up to 4.4
Fix:
No patched version reported
Disclosed:
Mar 11, 2024

CVE-2023-4729 on NVD →

LadiApp <= 4.4 - Cross-Site Request Forgery via save_config()

medium

The LadiApp plugin for WordPress is vulnerable to Cross-Site Request Forgery due to a missing nonce check on the save_config() function in versions up to, and including, 4.3. This makes it possible for unauthenticated attackers to update the 'ladipage_config' option via a forged request granted they can trick a site ad...

CVSS:
4.3
Affected:
up to 4.3
Fix:
No patched version reported
Disclosed:
Mar 11, 2024

CVE-2023-4629 on NVD →

LadiApp: Landing Page, PopupX, Marketing Automation, Affiliate Marketing… <= 4.4 - Cross-Site Request Forgery via init_endpoint

medium

The LadiApp plugn for WordPress is vulnerable to Cross-Site Request Forgery due to a missing nonce check on the init_endpoint() function hooked via 'init' in versions up to, and including, 4.4. This makes it possible for unauthenticated attackers to modify a variety of settings, via a forged request granted they can tr...

CVSS:
4.3
Affected:
up to 4.4
Fix:
No patched version reported
Disclosed:
Mar 11, 2024

CVE-2023-4731 on NVD →

LadiApp <= 4.4 - Cross-Site Request Forgery via ladiflow_save_hook()

medium

The LadiApp plugin for WordPress is vulnerable to Cross-Site Request Forgery due to a missing nonce check on the ladiflow_save_hook() function in versions up to, and including, 4.4. This makes it possible for unauthenticated attackers to update the 'ladiflow_hook_configs' option via a forged request granted they can tr...

CVSS:
4.3
Affected:
up to 4.4
Fix:
No patched version reported
Disclosed:
Mar 11, 2024

CVE-2023-4628 on NVD →

LadiApp <= 4.3 - Missing Authorization

medium

The LadiApp plugin for WordPress is vulnerable to unauthorized access of data, modification of data, or loss of data due to a missing capability check on an unknown function in versions up to, and including, 4.3. This makes it possible for authenticated attackers, with subscriber-level access and above, to make use of...

CVSS:
4.3
Affected:
up to 4.3
Fix:
No patched version reported
Disclosed:
Nov 28, 2023

CVE-2023-49158 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database