plugin

Miniorange Malware Protection Vulnerabilities

4 known security issues reported for the Miniorange Malware Protection WordPress plugin. Most recent disclosed Mar 13, 2024.

1 critical 3 medium

Running Miniorange Malware Protection on your site? Check whether your installed version is affected.

Scan your site free

Malware Scanner <= 4.7.2 and Web Application Firewall <= 2.1.1 - Unauthenticated Privilege Escalation

critical

The Malware Scanner plugin and the Web Application Firewall plugin for WordPress (both by MiniOrange) are vulnerable to privilege escalation due to a missing capability check on the mo_wpns_init() function in all versions up to, and including, 4.7.2 (for Malware Scanner) and 2.1.1 (for Web Application Firewall). This m...

CVSS:
9.8
Affected:
up to 4.7.2
Fixed in:
4.7.3
Disclosed:
Mar 13, 2024

CVE-2024-2172 on NVD →

Malware Scanner <= 4.7.2 - Authenticated (Administrator+) SQL Injection

medium

The Malware Scanner plugin for WordPress is vulnerable to SQL Injection via an unknown parameter in all versions up to, and including, 4.7.2 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with...

CVSS:
6.6
Affected:
up to 4.7.2
Fixed in:
4.7.3
Disclosed:
Feb 12, 2024

CVE-2024-25902 on NVD →

Malware Scanner <= 4.7.1 - IP Spoofing

medium

The Malware Scanner plugin for WordPress is vulnerable to IP Address Spoofing in all versions up to, and including, 4.7.1 due to insufficient IP address validation and use of user-supplied HTTP headers as a primary method for IP retrieval. This makes it possible for unauthenticated attackers to bypass IP blocking funct...

CVSS:
5.3
Affected:
up to 4.7.1
Fixed in:
4.7.2
Disclosed:
Dec 29, 2023

CVE-2023-52176 on NVD →

miniOrange’s Malware Scanner <= 4.5.5 - Cross-Site Scripting

medium

The Malware Scanner WordPress plugin before 4.5.2 does not sanitise and escape some of its settings, leading to malicious users with administrator privileges to store malicious Javascript code leading to Cross-Site Scripting attacks when unfiltered_html is disallowed (for example in multisite setup)

CVSS:
4.8
Affected:
up to 4.5.1
Fixed in:
4.5.2
Disclosed:
Jun 6, 2022

CVE-2022-1995 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database