plugin

Posti Shipping Vulnerabilities

6 known security issues reported for the Posti Shipping WordPress plugin. Most recent disclosed Dec 16, 2024.

3 medium

Running Posti Shipping on your site? Check whether your installed version is affected.

Scan your site free

Posti Shipping [posti-shipping] < 3.10.4

unknown

[en] Cross-Site Request Forgery (CSRF) vulnerability in Posti Posti Shipping allows Cross Site Request Forgery.This issue affects Posti Shipping: from n/a through 3.10.3.

Affected:
up to 3.10.4
Fixed in:
3.10.4
Disclosed:
Dec 16, 2024

CVE-2024-56005 on NVD →

Posti Shipping <= 3.10.3 - Cross-Site Request Forgery

medium

The Posti Shipping plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.10.3. This is due to missing or incorrect nonce validation on several functions. This makes it possible for unauthenticated attackers to change plugin settins via a forged request granted they can tri...

CVSS:
4.3
Affected:
up to 3.10.3
Fixed in:
3.10.4
Disclosed:
Dec 14, 2024

CVE-2024-56005 on NVD →

Posti Shipping [posti-shipping] < 3.10.4

unknown

[en] The Posti Shipping plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.10.3. This is due to missing or incorrect nonce validation on the generate_notices_html() function. This makes it possible for unauthenticated attackers to inject malicious web scripts via a...

Affected:
up to 3.10.4
Fixed in:
3.10.4
Disclosed:
Dec 4, 2024

CVE-2024-10832 on NVD →

Posti Shipping <= 3.10.3 - Reflected Cross-Site Scripting

medium

The Posti Shipping plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the account_number and secret_key parameters in all versions up to, and including, 3.10.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web s...

CVSS:
6.1
Affected:
up to 3.10.3
Fixed in:
3.10.4
Disclosed:
Dec 3, 2024

CVE-2024-10832 on NVD →

Posti Shipping <= 3.10.2 - Full Path Disclosure

medium

The Posti Shipping plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 3.10.2. This makes it possible for unauthenticated attackers to retrieve the full path of the web application, which can be used to aid other attacks. The information displayed is not useful on its own, a...

CVSS:
5.3
Affected:
up to 3.10.2
Fixed in:
3.10.3
Disclosed:
Nov 28, 2024

CVE-2024-50512 on NVD →

Posti Shipping [posti-shipping] < 3.10.3

unknown

[en] Generation of Error Message Containing Sensitive Information vulnerability in Posti Posti Shipping allows Retrieve Embedded Sensitive Data.This issue affects Posti Shipping: from n/a through 3.10.2.

Affected:
up to 3.10.3
Fixed in:
3.10.3
Disclosed:
Oct 30, 2024

CVE-2024-50512 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database