plugin

Mingle Forum Vulnerabilities

22 known security issues reported for the Mingle Forum WordPress plugin. Most recent disclosed May 15, 2015.

1 critical 5 high 1 medium

Running Mingle Forum on your site? Check whether your installed version is affected.

Scan your site free

Mingle Forum [mingle-forum] < 1.0.31 (closed)

unknown

This plugin is prone to cross site scripting and full path disclosure vulnerabilities. Update plugin.

Affected:
up to 1.0.31
Fixed in:
1.0.31
Disclosed:
May 15, 2015

Mingle Forum [mingle-forum] < 1.0.33.2 (closed)

unknown

Because of this vulnerability, the attackers can inject arbitrary JavaScript or HTML code. Update the plugin.

Affected:
up to 1.0.33.2
Fixed in:
1.0.33.2
Disclosed:
May 15, 2015

Mingle Forum <= 1.0.32.1 - SQL Injection

high

Multiple SQL injection vulnerabilities in fs-admin/fs-admin.php in the Mingle Forum plugin 1.0.32.1 and other versions before 1.0.33 for WordPress allow remote authenticated users to execute arbitrary SQL commands via the (1) delete_usrgrp[] parameter in a delete_usergroups action, (2) usergroup parameter in an add_use...

CVSS:
8.8
Affected:
up to 1.0.32.1
Fixed in:
1.0.33
Disclosed:
Aug 1, 2014

CVE-2012-5327 on NVD →

Mingle Forum <= 1.0.32.1 - SQL Injection

high

Multiple SQL injection vulnerabilities in the Mingle Forum plugin 1.0.32.1 and other versions before 1.0.33 for WordPress might allow remote authenticated users to execute arbitrary SQL commands via the (1) memberid or (2) groupid parameters in a removemember action or (3) id parameter to fs-admin/fs-admin.php, or (4)...

CVSS:
8.8
Affected:
up to 1.0.33
Fixed in:
1.0.33
Disclosed:
Aug 1, 2014

CVE-2012-5328 on NVD →

Mingle Forum < 1.0.34 - Unauthenticated SQL Injection

high

The Mingle Forum plugin for WordPress is vulnerable to generic SQL Injection in versions up to 1.0.34 due to insufficient escaping on the user-supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into alre...

CVSS:
8.8
Affected:
up to 1.0.34
Fixed in:
1.0.34
Disclosed:
Aug 1, 2014

Mingle Forum [mingle-forum] < 1.0.34

unknown

The Mingle Forum plugin for WordPress is vulnerable to generic SQL Injection in versions up to 1.0.34 due to insufficient escaping on the user-supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into alre...

Affected:
up to 1.0.34
Fixed in:
1.0.34
Disclosed:
Aug 1, 2014

Mingle Forum [mingle-forum] < 1.0.34 (closed)

unknown

[en] Multiple SQL injection vulnerabilities in wpf.class.php in the Mingle Forum plugin before 1.0.34 for WordPress allow remote attackers to execute arbitrary SQL commands via the id parameter in a viewtopic (1) remove_post, (2) sticky, or (3) closed action or (4) thread parameter in a postreply action to index.php.

Affected:
up to 1.0.34
Fixed in:
1.0.34
Disclosed:
Apr 2, 2014

CVE-2013-0735 on NVD →

Mingle Forum [mingle-forum] < 1.0.34 (closed)

unknown

[en] Multiple cross-site scripting (XSS) vulnerabilities in the Mingle Forum plugin before 1.0.34 for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) search_words parameter in a search action to wpf.class.php or (2) togroupusers parameter in an add_user_togroup action to fs-admin/fs-...

Affected:
up to 1.0.34
Fixed in:
1.0.34
Disclosed:
Mar 28, 2014

CVE-2013-0734 on NVD →

Mingle Forum [mingle-forum] < 1.0.35 (closed)

unknown

[en] Multiple cross-site request forgery (CSRF) vulnerabilities in the Mingle Forum plugin 1.0.34 and possibly earlier for WordPress allow remote attackers to hijack the authentication of administrators for requests that (1) modify user privileges or (2) conduct cross-site scripting (XSS) attacks via unspecified vector...

Affected:
up to 1.0.35
Fixed in:
1.0.35
Disclosed:
Oct 9, 2013

CVE-2013-0736 on NVD →

Mingle Forum <= 1.0.33.3 - SQL Injection

critical

Multiple SQL injection vulnerabilities in wpf.class.php in the Mingle Forum plugin before 1.0.34 for WordPress allow remote attackers to execute arbitrary SQL commands via the id parameter in a viewtopic (1) remove_post, (2) sticky, or (3) closed action or (4) thread parameter in a postreply action to index.php.

CVSS:
9.8
Affected:
up to 1.0.33.3
Fixed in:
1.0.34
Disclosed:
Feb 20, 2013

CVE-2013-0735 on NVD →

Mingle Forum <= 1.0.33.3 - Stored Cross-Site Scripting

high

Multiple cross-site scripting (XSS) vulnerabilities in the Mingle Forum plugin before 1.0.34 for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) search_words parameter in a search action to wpf.class.php or (2) togroupusers parameter in an add_user_togroup action to fs-admin/fs-admin...

CVSS:
7.2
Affected:
up to 1.0.33.3
Fixed in:
1.0.34
Disclosed:
Feb 20, 2013

CVE-2013-0734 on NVD →

Mingle Forum <= 1.0.34 - Cross-Site Request Forgery

high

Multiple cross-site request forgery (CSRF) vulnerabilities in the Mingle Forum plugin 1.0.34 and possibly earlier for WordPress allow remote attackers to hijack the authentication of administrators for requests that (1) modify user privileges or (2) conduct cross-site scripting (XSS) attacks via unspecified vectors.

CVSS:
8.8
Affected:
up to 1.0.34
Fixed in:
1.0.35
Disclosed:
Jan 2, 2013

CVE-2013-0736 on NVD →

Mingle Forum [mingle-forum] < 1.0.33 (closed)

unknown

[en] Multiple SQL injection vulnerabilities in the Mingle Forum plugin 1.0.32.1 and other versions before 1.0.33 for WordPress might allow remote authenticated users to execute arbitrary SQL commands via the (1) memberid or (2) groupid parameters in a removemember action or (3) id parameter to fs-admin/fs-admin.php, or...

Affected:
up to 1.0.33
Fixed in:
1.0.33
Disclosed:
Oct 8, 2012

CVE-2012-5328 on NVD →

Mingle Forum [mingle-forum] < 1.0.33 (closed)

unknown

[en] Multiple SQL injection vulnerabilities in fs-admin/fs-admin.php in the Mingle Forum plugin 1.0.32.1 and other versions before 1.0.33 for WordPress allow remote authenticated users to execute arbitrary SQL commands via the (1) delete_usrgrp[] parameter in a delete_usergroups action, (2) usergroup parameter in an ad...

Affected:
up to 1.0.33
Fixed in:
1.0.33
Disclosed:
Oct 8, 2012

CVE-2012-5327 on NVD →

Mingle Forum <= 1.0.33 - Cross-Site Scripting

medium

The Mingle Forum plugin for WordPress is vulnerable to Cross-Site Scripting via several parameters in versions up to, and including, 1.0.33 due to insufficient input sanitization and output escaping. This makes it possible for attackers to inject arbitrary web scripts that execute in a victim's browser.

CVSS:
6.1
Affected:
up to 1.0.33
Fixed in:
1.0.33.2
Disclosed:
May 15, 2012

Mingle Forum [mingle-forum] < 1.0.33.2

unknown

The Mingle Forum plugin for WordPress is vulnerable to Cross-Site Scripting via several parameters in versions up to, and including, 1.0.33 due to insufficient input sanitization and output escaping. This makes it possible for attackers to inject arbitrary web scripts that execute in a victim's browser.

Affected:
up to 1.0.33.2
Fixed in:
1.0.33.2
Disclosed:
May 15, 2012

Mingle Forum [mingle-forum] < 1.0.32 (closed)

unknown

Mingle Forum plugin is prone to an SQL injection. This vulnerability allows an attacker to modify data, alter queries to the application SQL database, compromise the access and application or exploit hidden vulnerabilities in the underlying database. Upgrade the plugin.

Affected:
up to 1.0.32
Fixed in:
1.0.32
Disclosed:
Sep 27, 2011

Mingle Forum [mingle-forum] < 1.0.27 (closed)

unknown

There exist multiple vulnerabilities in Mingle Forum plugin for WordPress: 1. There is a SQL injection that reads application data. It is in the RSS feed generator. An attacker can retrieve information from the MySql database by crafting specific URLs. 2. SQL injection is in the edit post functionality. An attacke...

Affected:
up to 1.0.27
Fixed in:
1.0.27
Disclosed:
Jan 8, 2011

Mingle Forum [mingle-forum] < 1.0.31 (closed)

unknown

The mingle-forum WordPress plugin was affected by a XSS &amp; FPD security vulnerability.

Affected:
up to 1.0.31
Fixed in:
1.0.31

Mingle Forum [mingle-forum] <= 1.0.26 (unfixed + closed)

unknown

The mingle-forum WordPress plugin was affected by a Multiple Vulnerabilities security vulnerability.

Affected:
up to 1.0.26
Fix:
No patched version reported

Mingle Forum [mingle-forum] <= 1.0.31 (unfixed + closed)

unknown

The mingle-forum WordPress plugin was affected by a SQL Injection security vulnerability.

Affected:
up to 1.0.31
Fix:
No patched version reported

Mingle Forum [mingle-forum] < 1.0.33.2 (closed)

unknown

The mingle-forum WordPress plugin was affected by a Cross Site Scripting security vulnerability.

Affected:
up to 1.0.33.2
Fixed in:
1.0.33.2

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database