MAZ Loader – Preloader Builder for WordPress <= 1.4.0 - Cross-Site Request Forgery
medium
The MAZ Loader WordPress plugin before 1.4.1 does not enforce nonce checks, which allows attackers to make administrators delete arbitrary loaders via a CSRF attack
- CVSS:
- 4.3
- Affected:
- up to 1.4.0
- Fixed in:
- 1.4.1
- Disclosed:
- Oct 25, 2021
CVE-2021-24668 on NVD →
MAZ Loader – Preloader Builder for WordPress <= 1.3.2 - SQL Injection
high
The MAZ Loader – Preloader Builder for WordPress plugin before 1.3.3 does not validate or escape the loader_id parameter of the mzldr shortcode, which allows users with a role as low as Contributor to perform SQL injection.
- CVSS:
- 8.8
- Affected:
- up to 1.3.3
- Fixed in:
- 1.3.3
- Disclosed:
- Oct 11, 2021
CVE-2021-24669 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database