Materialis Companion <= 1.3.52 - Missing Authorization
medium
The Materialis Companion plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 1.3.52. This makes it possible for authenticated attackers, with subscriber-level access and above, to perform an unauthorized action.
- CVSS:
- 4.3
- Affected:
- up to 1.3.52
- Fixed in:
- 1.3.53
- Disclosed:
- Jan 24, 2026
CVE-2026-24543 on NVD →
Materialis Companion [materialis-companion] <= 1.3.52 (unfixed)
unknown
[en] Missing Authorization vulnerability in Horea Radu Materialis Companion materialis-companion allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Materialis Companion: from n/a through <= 1.3.52.
- Affected:
- up to 1.3.52
- Fix:
- No patched version reported
- Disclosed:
- Jan 23, 2026
CVE-2026-24543 on NVD →
Materialis Companion [materialis-companion] < 1.3.42
unknown
[en] The Materialis Companion plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's materialis_contact_form shortcode in all versions up to, and including, 1.3.41 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated...
- Affected:
- up to 1.3.42
- Fixed in:
- 1.3.42
- Disclosed:
- Jun 6, 2024
CVE-2024-4707 on NVD →
Materialis Companion <= 1.3.41 - Authenticated (Contributor+) Store Cross-Site Scripting via materialis_contact_form Shortcode
medium
The Materialis Companion plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's materialis_contact_form shortcode in all versions up to, and including, 1.3.41 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated atta...
- CVSS:
- 6.4
- Affected:
- up to 1.3.41
- Fixed in:
- 1.3.42
- Disclosed:
- Jun 5, 2024
CVE-2024-4707 on NVD →
Materialis Companion [materialis-companion] < 1.3.40
unknown
[en] The Materialis Companion WordPress plugin before 1.3.40 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users su...
- Affected:
- up to 1.3.40
- Fixed in:
- 1.3.40
- Disclosed:
- Feb 6, 2023
CVE-2022-4762 on NVD →
Materialis Companion <= 1.3.39 - Authenticated (Contributor+) Stored Cross-Site Scripting
medium
The Materialis Companion plugin for WordPress is vulnerable to Stored Cross-Site Scripting via an unknown shortcode in versions up to, and including, 1.3.39 due to insufficient input sanitization and output escaping. This makes it possible for contributor-level attackers to inject arbitrary web scripts in pages that wi...
- CVSS:
- 6.4
- Affected:
- up to 1.3.39
- Fixed in:
- 1.3.40
- Disclosed:
- Jan 13, 2023
CVE-2022-4762 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database