Active Directory Integration / LDAP Integration [ldap-login-for-intranet-sites] < 3.6.95
unknown
Update the WordPress Active Directory Integration / LDAP Integration plugin to the latest available version (at least 3.6.95).
WPScanTeam discovered and reported this Cross Site Scripting (XSS) vulnerability in WordPress Active Directory Integration / LDAP Integration Plugin. This could allow a malicious actor to injec...
- Affected:
- up to 3.6.95
- Fixed in:
- 3.6.95
- Disclosed:
- Oct 18, 2023
Active Directory Integration / LDAP Integration [ldap-login-for-intranet-sites] < 4.1.10
unknown
[en] The Active Directory Integration / LDAP Integration WordPress plugin before 4.1.10 stores sensitive LDAP logs in a buffer file when an administrator wants to export said logs. Unfortunately, this log file is never removed, and remains accessible to any users knowing the URL to do so.
- Affected:
- up to 4.1.10
- Fixed in:
- 4.1.10
- Disclosed:
- Oct 16, 2023
CVE-2023-5003 on NVD →
Active Directory Integration / LDAP Integration [ldap-login-for-intranet-sites] < 4.2
unknown
[en] The Active Directory Integration / LDAP Integration plugin for WordPress is vulnerable to LDAP Passback in versions up to, and including, 4.1.10. This is due to insufficient validation when changing the LDAP server. This makes it possible for authenticated attackers, with administrative access and above, to change...
- Affected:
- up to 4.2
- Fixed in:
- 4.2
- Disclosed:
- Sep 26, 2023
CVE-2023-4506 on NVD →
Active Directory Integration / LDAP Integration <= 4.1.9 - Sensitive Information Exposure
high
The Active Directory Integration / LDAP Integration plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 4.1.9 via a publicly accessible LDAP log buffer created when an administrator exports the logs. This makes it possible for unauthenticated attackers to visit the log...
- CVSS:
- 7.5
- Affected:
- up to 4.1.9
- Fixed in:
- 4.1.10
- Disclosed:
- Sep 25, 2023
CVE-2023-4506 on NVD →
Active Directory Integration / LDAP Integration <= 4.1.9 - Unauthenticated Information Disclosure
medium
The Active Directory Integration / LDAP Integration plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 4.1.9 via log files that are left over and not deleted. This makes it possible for unauthenticated attackers to extract potentially sensitive data including errors and inf...
- CVSS:
- 5.3
- Affected:
- up to 4.1.9
- Fixed in:
- 4.1.10
- Disclosed:
- Sep 25, 2023
CVE-2023-5003 on NVD →
Active Directory Integration / LDAP Integration <= 4.1.10 - LDAP Passback
low
The Active Directory Integration / LDAP Integration plugin for WordPress is vulnerable to LDAP Passback in versions up to, and including, 4.1.10. This is due to insufficient validation when changing the LDAP server. This makes it possible for authenticated attackers, with administrative access and above, to change the...
- CVSS:
- 2.2
- Affected:
- up to 4.1.10
- Fixed in:
- 4.2
- Disclosed:
- Sep 25, 2023
CVE-2023-4506 on NVD →
Active Directory Integration / LDAP Integration [ldap-login-for-intranet-sites] < 4.1.6
unknown
[en] The Active Directory Integration / LDAP Integration plugin for WordPress is vulnerable to LDAP Injection in versions up to, and including, 4.1.5. This is due to insufficient escaping on the supplied username value. This makes it possible for unauthenticated attackers to extract potentially sensitive information fr...
- Affected:
- up to 4.1.6
- Fixed in:
- 4.1.6
- Disclosed:
- Jun 29, 2023
CVE-2023-3447 on NVD →
Active Directory Integration / LDAP Integration <= 4.1.5 - Authenticated (Subscriber+) LDAP Injection
high
The Active Directory Integration / LDAP Integration plugin for WordPress is vulnerable to LDAP Injection in versions up to, and including, 4.1.5. This is due to insufficient escaping on the supplied username value. This makes it possible for attackers, with an existing account on a vulnerable WordPress instance, to ext...
- CVSS:
- 7.6
- Affected:
- up to 4.1.5
- Fixed in:
- 4.1.6
- Disclosed:
- Jun 28, 2023
CVE-2023-3447 on NVD →
Active Directory Integration / LDAP Integration [ldap-login-for-intranet-sites] < 4.1.5
unknown
[en] The Active Directory Integration plugin for WordPress is vulnerable to time-based SQL Injection via the orderby and order parameters in versions up to, and including, 4.1.4 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possi...
- Affected:
- up to 4.1.5
- Fixed in:
- 4.1.5
- Disclosed:
- Jun 9, 2023
CVE-2023-2484 on NVD →
Active Directory Integration / LDAP Integration [ldap-login-for-intranet-sites] < 4.1.5
unknown
[en] The Active Directory Integration plugin for WordPress is vulnerable to Cross-Site Request Forgery leading to time-based SQL Injection via the orderby and order parameters in versions up to, and including, 4.1.4 due to missing nonce verification on the get_users function and insufficient escaping on the user suppli...
- Affected:
- up to 4.1.5
- Fixed in:
- 4.1.5
- Disclosed:
- Jun 9, 2023
CVE-2023-2599 on NVD →
Active Directory Integration / LDAP Integration [ldap-login-for-intranet-sites] < 4.1.1
unknown
[en] The Active Directory Integration / LDAP Integration WordPress plugin before 4.1.1 does not have proper authorization or nonce values for some POST requests, leading to unauthenticated data disclosure.
- Affected:
- up to 4.1.1
- Fixed in:
- 4.1.1
- Disclosed:
- May 15, 2023
CVE-2023-0812 on NVD →
Active Directory Integration / LDAP Integration <= 4.1.4 - Authenticated (Administrator+) SQL Injection
high
The Active Directory Integration plugin for WordPress is vulnerable to time-based SQL Injection via the orderby and order parameters in versions up to, and including, 4.1.4 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible f...
- CVSS:
- 7.2
- Affected:
- up to 4.1.4
- Fixed in:
- 4.1.5
- Disclosed:
- May 12, 2023
CVE-2023-2484 on NVD →
Active Directory Integration / LDAP Integration <= 4.1.4 - Cross-Site Request Forgery to SQL Injection
low
The Active Directory Integration plugin for WordPress is vulnerable to Cross-Site Request Forgery leading to time-based SQL Injection via the orderby and order parameters in versions up to, and including, 4.1.4 due to missing nonce verification on the get_users function and insufficient escaping on the user supplied pa...
- CVSS:
- 3.1
- Affected:
- up to 4.1.4
- Fixed in:
- 4.1.5
- Disclosed:
- May 12, 2023
CVE-2023-2599 on NVD →
Active Directory Integration / LDAP Integration <= 4.1.0 - Unauthenticated Information Disclosure
medium
The Active Directory Integration / LDAP Integration plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 4.1.0 via the 'test_attribute_configuration'. This can allow unauthenticated attackers to extract sensitive data including configuration settings.
- CVSS:
- 5.3
- Affected:
- up to 4.1.0
- Fixed in:
- 4.1.1
- Disclosed:
- Apr 19, 2023
CVE-2023-0812 on NVD →
Active Directory Integration / LDAP Integration <= 3.6.94 - Reflected Cross-Site Scripting
medium
The Active Directory Integration / LDAP Integration plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘test_username’ parameter in versions up to, and including 3.6.94 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject ar...
- CVSS:
- 6.1
- Affected:
- up to 3.6.95
- Fixed in:
- 3.6.95
- Disclosed:
- Oct 18, 2021
Active Directory Integration / LDAP Integration [ldap-login-for-intranet-sites] < 3.6.95
unknown
The Active Directory Integration / LDAP Integration plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘test_username’ parameter in versions up to, and including 3.6.94 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject ar...
- Affected:
- up to 3.6.95
- Fixed in:
- 3.6.95
- Disclosed:
- Oct 18, 2021
Active Directory Integration / LDAP Integration [ldap-login-for-intranet-sites] < 3.6.95
unknown
The plugin does not escape the test_username parameter before outputting it back in the settings page, leading to a Reflected Cross-Site Scripting issue
- Affected:
- up to 3.6.95
- Fixed in:
- 3.6.95
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database