plugin

Molongui Authorship Vulnerabilities

12 known security issues reported for the Molongui Authorship WordPress plugin. Most recent disclosed Dec 9, 2024.

6 medium

Running Molongui Authorship on your site? Check whether your installed version is affected.

Scan your site free

Molongui Authorship – Author Boxes, Guest Authors &amp; Co-Authors for WordPress [molongui-authorship] < 4.7.4

unknown

[en] Missing Authorization vulnerability in Molongui Molongui allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Molongui: from n/a through 4.7.3.

Affected:
up to 4.7.4
Fixed in:
4.7.4
Disclosed:
Dec 9, 2024

CVE-2023-50876 on NVD →

Molongui Authorship – Author Boxes, Guest Authors &amp; Co-Authors for WordPress [molongui-authorship] < 4.7.8

unknown

[en] Authorization Bypass Through User-Controlled Key vulnerability in Molongui.This issue affects Molongui: from n/a through 4.7.7.

Affected:
up to 4.7.8
Fixed in:
4.7.8
Disclosed:
Mar 29, 2024

CVE-2024-30507 on NVD →

Molongui <= 4.7.7 - Authenticated (Author+) Insecure Direct Object Reference

medium

The Author Box, Guest Author and Co-Authors for Your Posts – Molongui plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 4.7.7 due to missing validation on a user controlled key. This makes it possible for authenticated attackers, with author-level access and ab...

CVSS:
4.3
Affected:
up to 4.7.7
Fixed in:
4.7.8
Disclosed:
Mar 28, 2024

CVE-2024-30507 on NVD →

Molongui Authorship – Author Boxes, Guest Authors &amp; Co-Authors for WordPress [molongui-authorship] < 4.7.8

unknown

[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Molongui allows Stored XSS.This issue affects Molongui: from n/a through 4.7.7.

Affected:
up to 4.7.8
Fixed in:
4.7.8
Disclosed:
Mar 27, 2024

CVE-2024-29764 on NVD →

Molongui <= 4.7.7 - Authenticated (Author+) Stored Cross-Site Scripting

medium

The Molongui plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 4.7.7 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with author-level access and above, to inject arbitrary web scripts in pages that will ex...

CVSS:
5.5
Affected:
up to 4.7.7
Fixed in:
4.7.8
Disclosed:
Mar 25, 2024

CVE-2024-29764 on NVD →

Molongui Authorship – Author Boxes, Guest Authors &amp; Co-Authors for WordPress [molongui-authorship] < 4.7.5

unknown

[en] The Author Box, Guest Author and Co-Authors for Your Posts – Molongui plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.7.4 via the 'ma_debu' parameter. This makes it possible for unauthenticated attackers to extract sensitive data including post author em...

Affected:
up to 4.7.5
Fixed in:
4.7.5
Disclosed:
Feb 5, 2024

CVE-2023-7014 on NVD →

Author Box, Guest Author and Co-Authors for Your Posts – Molongui <= 4.7.4 - Information Exposure via ma_debug

medium

The Author Box, Guest Author and Co-Authors for Your Posts – Molongui plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.7.4 via the 'ma_debu' parameter. This makes it possible for unauthenticated attackers to extract sensitive data including post author emails...

CVSS:
5.3
Affected:
up to 4.7.4
Fixed in:
4.7.5
Disclosed:
Jan 16, 2024

CVE-2023-7014 on NVD →

Molongui <= 4.7.3 - Missing Authorization

medium

The Molongui plugin for WordPress is vulnerable to unauthorized modification and access of data due to missing capability checks on the authorship_export_options() and authorship_save_options() functions hooked via AJAX in versions up to, and including, 4.7.3. This makes it possible for authenticated attackers, with su...

CVSS:
5.4
Affected:
up to 4.7.3
Fixed in:
4.7.4
Disclosed:
Dec 26, 2023

CVE-2023-50876 on NVD →

Molongui Authorship – Author Boxes, Guest Authors &amp; Co-Authors for WordPress [molongui-authorship] < 4.6.20

unknown

[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Molongui Author Box, Guest Author and Co-Authors for Your Posts – Molongui allows Stored XSS.This issue affects Author Box, Guest Author and Co-Authors for Your Posts – Molongui: from n/a through 4.6.19.

Affected:
up to 4.6.20
Fixed in:
4.6.20
Disclosed:
Nov 30, 2023

CVE-2023-39921 on NVD →

Molongui <= 4.6.19 - Authenticated (Administrator+) Stored Cross-Site Scripting

medium

The Author Box, Guest Author and Co-Authors for Your Posts – Molongui plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 4.6.19 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with adm...

CVSS:
4.4
Affected:
up to 4.6.19
Fixed in:
4.6.20
Disclosed:
Nov 28, 2023

CVE-2023-39921 on NVD →

Molongui Authorship – Author Boxes, Guest Authors &amp; Co-Authors for WordPress [molongui-authorship] < 4.6.20

unknown

[en] Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Molongui Author Box for Authors, Co-Authors, Multiple Authors and Guest Authors – Molongui plugin <= 4.6.19 versions.

Affected:
up to 4.6.20
Fixed in:
4.6.20
Disclosed:
Sep 4, 2023

CVE-2023-39164 on NVD →

Molongui <= 4.6.19 - Reflected Cross-Site Scripting

medium

The Molongui plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'page' parameter in versions up to, and including, 4.6.19 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute...

CVSS:
6.1
Affected:
up to 4.6.19
Fixed in:
4.6.20
Disclosed:
Jul 26, 2023

CVE-2023-39164 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database