My Category Order <= 4.3 - Cross-Site Request Forgery to Cross-Site Scripting
high
The My Category Order plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 4.3 due to missing nonce validation. This makes it possible for attackers to inject arbitrary web scripts that execute in a victim's browser granted they can trick a site's administrator into perform...
- CVSS:
- 8.8
- Affected:
- up to 4.3
- Fixed in:
- 4.4.2
- Disclosed:
- Aug 13, 2015
my-category-order <= 2.8.7 - SQL Injection
medium
SQL injection vulnerability in mycategoryorder.php in the My Category Order plugin 2.8.7 and earlier for WordPress allows remote attackers to execute arbitrary SQL commands via the parentID parameter in an act_OrderCategories action to wp-admin/post-new.php.
- CVSS:
- 6.4
- Affected:
- up to 2.8.7
- Fixed in:
- 3.0.1
- Disclosed:
- Jul 15, 2009
CVE-2009-4748 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database