plugin

No Update Nag Vulnerabilities

1 known security issue reported for the No Update Nag WordPress plugin. Most recent disclosed Aug 8, 2024.

1 medium

Running No Update Nag on your site? Check whether your installed version is affected.

Scan your site free

No Update Nag <= 1.4.12 - Unauthenticated Full Path Disclosure

medium

The No Update Nag plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 1.4.12. This is due to the plugin allowing direct access to the bootstrap.php file which has display_errors on. This makes it possible for unauthenticated attackers to retrieve the full path of the web app...

CVSS:
5.3
Affected:
up to 1.4.12
Fixed in:
1.4.13
Disclosed:
Aug 8, 2024

CVE-2024-7412 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database