plugin

Process Steps Template Designer Vulnerabilities

8 known security issues reported for the Process Steps Template Designer WordPress plugin. Most recent disclosed Jul 12, 2023.

1 high 1 medium

Running Process Steps Template Designer on your site? Check whether your installed version is affected.

Scan your site free

Process Steps Template Designer [process-steps-template-designer] < 1.3 (closed)

unknown

[en] The Process Steps Template Designer plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.2.1. This is due to missing or incorrect nonce validation on the save() function. This makes it possible for unauthenticated attackers to save field icons via a forged request gr...

Affected:
up to 1.3
Fixed in:
1.3
Disclosed:
Jul 12, 2023

CVE-2021-4413 on NVD →

Process Steps Template Designer [process-steps-template-designer] < 1.3 (closed)

unknown

[en] The Process Steps Template Designer plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.2.1. This makes it possible for unauthenticated attackers to conduct unspecified attacks via forged request granted they can trick a site administrator into performing an action...

Affected:
up to 1.3
Fixed in:
1.3
Disclosed:
Jun 7, 2023

CVE-2021-4349 on NVD →

Process Steps Template Designer [process-steps-template-designer] < 1.3 (closed)

unknown
Affected:
up to 1.3
Fixed in:
1.3
Disclosed:
Jun 7, 2023

CVE-2021-4342 on NVD →

Process Steps Template Designer <= 1.2.1 - Cross-Site Request Forgery

high

The Process Steps Template Designer plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.2.1. This makes it possible for unauthenticated attackers to conduct unspecified attacks via forged request granted they can trick a site administrator into performing an action such...

CVSS:
8.8
Affected:
up to 1.3
Fixed in:
1.3
Disclosed:
Mar 1, 2021

CVE-2021-4349 on NVD →

Process Steps Template Designer <= 1.2.1 - Cross-Site Request Forgery Bypass

medium

The Process Steps Template Designer plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.2.1. This is due to missing or incorrect nonce validation on the save() function. This makes it possible for unauthenticated attackers to save field icons via a forged request granted...

CVSS:
4.3
Affected:
up to 1.2.1
Fixed in:
1.3
Disclosed:
Mar 1, 2021

CVE-2021-4413 on NVD →

Process Steps Template Designer [process-steps-template-designer] < 1.3 (closed)

unknown

The Process Steps Template Designer plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.2.1. This makes it possible for unauthenticated attackers to conduct unspecified attacks via forged request granted they can trick a site administrator into performing an action such...

Affected:
up to 1.3
Fixed in:
1.3
Disclosed:
Mar 1, 2021

Process Steps Template Designer [process-steps-template-designer] < 1.3 (closed)

unknown

Cross-Site Request Forgery (CSRF) vulnerability found in WordPress Process Steps Template Designer plugin (versions <= 1.2.1).

Affected:
up to 1.3
Fixed in:
1.3
Disclosed:
Jan 12, 2021

Process Steps Template Designer [process-steps-template-designer] < 1.3 (closed)

unknown

Over 70 plugins and themes were vulnerable to Cross-Site Request Forgery due to improperly implemented nonce protection that could be bypassed.

Affected:
up to 1.3
Fixed in:
1.3

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database