plugin

Pixtypes Vulnerabilities

5 known security issues reported for the Pixtypes WordPress plugin. Most recent disclosed Sep 4, 2023.

2 medium

Running Pixtypes on your site? Check whether your installed version is affected.

Scan your site free

PixTypes [pixtypes] <= 1.4.15 (unfixed + closed)

unknown

[en] Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Pixelgrade PixTypes plugin <= 1.4.15 versions.

Affected:
up to 1.4.15
Fix:
No patched version reported
Disclosed:
Sep 4, 2023

CVE-2023-40205 on NVD →

PixTypes <= 1.4.15 - Reflected Cross-Site Scripting

medium

The PixTypes plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 1.4.15 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses...

CVSS:
6.1
Affected:
up to 1.4.15
Fixed in:
1.4.16
Disclosed:
Aug 11, 2023

CVE-2023-40205 on NVD →

PixTypes [pixtypes] < 1.4.15 (closed)

unknown

[en] Cross-Site Request Forgery (CSRF) vulnerability in Pixelgrade PixTypes plugin <= 1.4.14 versions.

Affected:
up to 1.4.15
Fixed in:
1.4.15
Disclosed:
Jul 11, 2023

CVE-2023-25487 on NVD →

PixTypes <= 1.4.14 - Cross-Site Request Forgery

medium

The PixTypes plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.4.14. This is due to missing or incorrect nonce validation on the save_pixtypes_settings() function. This makes it possible for unauthenticated attackers to modify theme settings in the plugin, via a forged...

CVSS:
4.3
Affected:
up to 1.4.14
Fixed in:
1.4.15
Disclosed:
Apr 7, 2023

CVE-2023-25487 on NVD →

PixTypes [pixtypes] < 1.4.15 (closed)

unknown

The PixTypes plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.4.14. This is due to missing or incorrect nonce validation on the save_pixtypes_settings() function. This makes it possible for unauthenticated attackers to modify theme settings in the plugin, via a forged...

Affected:
up to 1.4.15
Fixed in:
1.4.15
Disclosed:
Apr 7, 2023

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database