OneTone Companion <= 1.1.1 - Open Mailer
medium
The OneTone Companion plugin for WordPress suffers from an Open Mailer vulnerability in versions up to, and including, 1.1.1. This is due to a lack of authorization on the onetone_contact function which is reachable via nopriv AJAX call. This makes it possible for unauthenticated attackers to send emails with any conte...
- CVSS:
- 5.8
- Affected:
- up to 1.1.1
- Fix:
- No patched version reported
- Disclosed:
- Aug 18, 2022
OneTone <= 3.0.6 & OneTone Companion <= 1.1.1 - Unauthenticated Settings Update
critical
includes/theme-functions.php in the OneTone theme through 3.0.6 for WordPress allows unauthenticated options changes.
- CVSS:
- 9.8
- Affected:
- up to 1.1.1
- Fix:
- No patched version reported
- Disclosed:
- Apr 3, 2020
CVE-2019-17230 on NVD →
OneTone <= 3.0.6 & OneTone Companion <= 1.1.1 - Stored Cross-Site Scripting
high
includes/theme-functions.php in the OneTone theme through 3.0.6 for WordPress has multiple stored XSS issues.
- CVSS:
- 7.2
- Affected:
- up to 1.1.1
- Fix:
- No patched version reported
- Disclosed:
- Apr 3, 2020
CVE-2019-17231 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database