Opal Estate [opal-estate] <= 1.6.11 (unfixed)
unknown
[en] The Opal Estate plugin for WordPress is vulnerable to featured property modifications in versions up to, and including, 1.6.11. This is due to missing capability checks on the opalestate_set_feature_property() and opalestate_remove_feature_property() functions. This makes it possible for unauthenticated attackers...
- Affected:
- up to 1.6.11
- Fix:
- No patched version reported
- Disclosed:
- Jul 1, 2023
CVE-2021-4388 on NVD →
Opal Estate [opal-estate] <= 1.6.11 (unfixed)
unknown
[en] The Opal Estate plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.6.11. This is due to missing or incorrect nonce validation on the opalestate_set_feature_property() and opalestate_remove_feature_property() functions. This makes it possible for unauthenticated att...
- Affected:
- up to 1.6.11
- Fix:
- No patched version reported
- Disclosed:
- Jul 1, 2023
CVE-2021-4387 on NVD →
Opal Estate [opal-estate] <= 1.6.11 (unfixed)
unknown
- Affected:
- up to 1.6.11
- Fix:
- No patched version reported
- Disclosed:
- Jun 7, 2023
CVE-2021-4342 on NVD →
Opal Estate <= 1.6.11 - Cross-Site Request Forgery Bypass
medium
The Opal Estate plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.6.11. This is due to missing or incorrect nonce validation on the opalestate_set_feature_property() and opalestate_remove_feature_property() functions. This makes it possible for unauthenticated attacker...
- CVSS:
- 4.3
- Affected:
- up to 1.6.11
- Fix:
- No patched version reported
- Disclosed:
- Aug 16, 2021
CVE-2021-4387 on NVD →
Opal Estate <= 1.6.11 - Missing Authorization
medium
The Opal Estate plugin for WordPress is vulnerable to featured property modifications in versions up to, and including, 1.6.11. This is due to missing capability checks on the opalestate_set_feature_property() and opalestate_remove_feature_property() functions. This makes it possible for unauthenticated attackers to s...
- CVSS:
- 4.3
- Affected:
- up to 1.6.11
- Fix:
- No patched version reported
- Disclosed:
- Aug 16, 2021
CVE-2021-4388 on NVD →
Opal Estate [opal-estate] <= 1.6.11 (unfixed + closed)
unknown
Cross-Site Request Forgery (CSRF) vulnerability discovered by Jerome Bruandet (NinTechNet) in WordPress Opal Estate plugin (versions <= 1.6.11).
- Affected:
- up to 1.6.11
- Fix:
- No patched version reported
- Disclosed:
- Aug 16, 2021
Opal Estate [opal-estate] <= 1.6.11
unknown
Over 70 plugins and themes were vulnerable to Cross-Site Request Forgery due to improperly implemented nonce protection that could be bypassed.
- Affected:
- up to 1.6.11
- Fixed in:
- 1.6.11
Opal Estate [opal-estate] <= 1.6.11 (unfixed + closed)
unknown
Multiple plugins are affected by CSRF issues due to a logic flaw in their CSRF checks, which could allow attackers to make users perform unwanted actions
rucy <= 0.4.4
wp-backgrounds-lite <= 2.3
wp-security-questions <= 1.0.5
photo-contest <= 1.0.6
opal-estate <= 1.6.11
rays-grid <= 1.2.2
- Affected:
- up to 1.6.11
- Fix:
- No patched version reported
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database