plugin

Opal Estate Vulnerabilities

8 known security issues reported for the Opal Estate WordPress plugin. Most recent disclosed Jul 1, 2023.

2 medium

Running Opal Estate on your site? Check whether your installed version is affected.

Scan your site free

Opal Estate [opal-estate] <= 1.6.11 (unfixed)

unknown

[en] The Opal Estate plugin for WordPress is vulnerable to featured property modifications in versions up to, and including, 1.6.11. This is due to missing capability checks on the opalestate_set_feature_property() and opalestate_remove_feature_property() functions. This makes it possible for unauthenticated attackers...

Affected:
up to 1.6.11
Fix:
No patched version reported
Disclosed:
Jul 1, 2023

CVE-2021-4388 on NVD →

Opal Estate [opal-estate] <= 1.6.11 (unfixed)

unknown

[en] The Opal Estate plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.6.11. This is due to missing or incorrect nonce validation on the opalestate_set_feature_property() and opalestate_remove_feature_property() functions. This makes it possible for unauthenticated att...

Affected:
up to 1.6.11
Fix:
No patched version reported
Disclosed:
Jul 1, 2023

CVE-2021-4387 on NVD →

Opal Estate [opal-estate] <= 1.6.11 (unfixed)

unknown
Affected:
up to 1.6.11
Fix:
No patched version reported
Disclosed:
Jun 7, 2023

CVE-2021-4342 on NVD →

Opal Estate <= 1.6.11 - Cross-Site Request Forgery Bypass

medium

The Opal Estate plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.6.11. This is due to missing or incorrect nonce validation on the opalestate_set_feature_property() and opalestate_remove_feature_property() functions. This makes it possible for unauthenticated attacker...

CVSS:
4.3
Affected:
up to 1.6.11
Fix:
No patched version reported
Disclosed:
Aug 16, 2021

CVE-2021-4387 on NVD →

Opal Estate <= 1.6.11 - Missing Authorization

medium

The Opal Estate plugin for WordPress is vulnerable to featured property modifications in versions up to, and including, 1.6.11. This is due to missing capability checks on the opalestate_set_feature_property() and opalestate_remove_feature_property() functions. This makes it possible for unauthenticated attackers to s...

CVSS:
4.3
Affected:
up to 1.6.11
Fix:
No patched version reported
Disclosed:
Aug 16, 2021

CVE-2021-4388 on NVD →

Opal Estate [opal-estate] <= 1.6.11 (unfixed + closed)

unknown

Cross-Site Request Forgery (CSRF) vulnerability discovered by Jerome Bruandet (NinTechNet) in WordPress Opal Estate plugin (versions <= 1.6.11).

Affected:
up to 1.6.11
Fix:
No patched version reported
Disclosed:
Aug 16, 2021

Opal Estate [opal-estate] <= 1.6.11

unknown

Over 70 plugins and themes were vulnerable to Cross-Site Request Forgery due to improperly implemented nonce protection that could be bypassed.

Affected:
up to 1.6.11
Fixed in:
1.6.11

Opal Estate [opal-estate] <= 1.6.11 (unfixed + closed)

unknown

Multiple plugins are affected by CSRF issues due to a logic flaw in their CSRF checks, which could allow attackers to make users perform unwanted actions rucy &lt;= 0.4.4 wp-backgrounds-lite &lt;= 2.3 wp-security-questions &lt;= 1.0.5 photo-contest &lt;= 1.0.6 opal-estate &lt;= 1.6.11 rays-grid &lt;= 1.2.2

Affected:
up to 1.6.11
Fix:
No patched version reported

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database