Malware Scanner <= 4.7.2 and Web Application Firewall <= 2.1.1 - Unauthenticated Privilege Escalation
critical
The Malware Scanner plugin and the Web Application Firewall plugin for WordPress (both by MiniOrange) are vulnerable to privilege escalation due to a missing capability check on the mo_wpns_init() function in all versions up to, and including, 4.7.2 (for Malware Scanner) and 2.1.1 (for Web Application Firewall). This m...
- CVSS:
- 9.8
- Affected:
- up to 4.7.2
- Fixed in:
- 4.7.3
- Disclosed:
- Mar 13, 2024
CVE-2024-2172 on NVD →
Malware Scanner <= 4.7.2 - Authenticated (Administrator+) SQL Injection
medium
The Malware Scanner plugin for WordPress is vulnerable to SQL Injection via an unknown parameter in all versions up to, and including, 4.7.2 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with...
- CVSS:
- 6.6
- Affected:
- up to 4.7.2
- Fixed in:
- 4.7.3
- Disclosed:
- Feb 12, 2024
CVE-2024-25902 on NVD →
Malware Scanner <= 4.7.1 - IP Spoofing
medium
The Malware Scanner plugin for WordPress is vulnerable to IP Address Spoofing in all versions up to, and including, 4.7.1 due to insufficient IP address validation and use of user-supplied HTTP headers as a primary method for IP retrieval. This makes it possible for unauthenticated attackers to bypass IP blocking funct...
- CVSS:
- 5.3
- Affected:
- up to 4.7.1
- Fixed in:
- 4.7.2
- Disclosed:
- Dec 29, 2023
CVE-2023-52176 on NVD →
miniOrange’s Malware Scanner <= 4.5.5 - Cross-Site Scripting
medium
The Malware Scanner WordPress plugin before 4.5.2 does not sanitise and escape some of its settings, leading to malicious users with administrator privileges to store malicious Javascript code leading to Cross-Site Scripting attacks when unfiltered_html is disallowed (for example in multisite setup)
- CVSS:
- 4.8
- Affected:
- up to 4.5.1
- Fixed in:
- 4.5.2
- Disclosed:
- Jun 6, 2022
CVE-2022-1995 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database