plugin

Radio Buttons For Taxonomies Vulnerabilities

6 known security issues reported for the Radio Buttons For Taxonomies WordPress plugin. Most recent disclosed Jul 1, 2023.

1 medium

Running Radio Buttons For Taxonomies on your site? Check whether your installed version is affected.

Scan your site free

Radio Buttons for Taxonomies [radio-buttons-for-taxonomies] < 2.0.6

unknown

[en] The Radio Buttons for Taxonomies plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.0.5. This is due to missing or incorrect nonce validation on the save_single_term() function. This makes it possible for unauthenticated attackers to save terms via a forged request...

Affected:
up to 2.0.6
Fixed in:
2.0.6
Disclosed:
Jul 1, 2023

CVE-2020-36740 on NVD →

Radio Buttons for Taxonomies [radio-buttons-for-taxonomies] < 2.0.6

unknown
Affected:
up to 2.0.6
Fixed in:
2.0.6
Disclosed:
Jun 7, 2023

CVE-2021-4342 on NVD →

Radio Buttons for Taxonomies <= 2.0.5 - Cross-Site Request Forgery Bypass

medium

The Radio Buttons for Taxonomies plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.0.5. This is due to missing or incorrect nonce validation on the save_single_term() function. This makes it possible for unauthenticated attackers to save terms via a forged request gran...

CVSS:
4.3
Affected:
up to 2.0.6
Fixed in:
2.0.6
Disclosed:
Sep 16, 2020

CVE-2020-36740 on NVD →

Radio Buttons for Taxonomies [radio-buttons-for-taxonomies] < 2.0.6

unknown

Cross-Site Request Forgery (CSRF) vulnerability found by Jerome Bruandet (NinTechNet) in WordPress Radio Buttons for Taxonomies plugin (versions <= 2.0.5).

Affected:
up to 2.0.6
Fixed in:
2.0.6
Disclosed:
Sep 16, 2020

Radio Buttons for Taxonomies [radio-buttons-for-taxonomies] < 2.0.6

unknown

NinTechNet discovered multiple WordPress plugins and themes vulnerable to Cross-Site Request Forgery (CSRF). The items only check the CSRF nonce if it has been provided, making them vulnerable to CSRF attacks if the nonce is removed. This is due to the confusing use of logic operators when verifying the nonces.

Affected:
up to 2.0.6
Fixed in:
2.0.6

Radio Buttons for Taxonomies [radio-buttons-for-taxonomies] < 2.0.6

unknown

Over 70 plugins and themes were vulnerable to Cross-Site Request Forgery due to improperly implemented nonce protection that could be bypassed.

Affected:
up to 2.0.6
Fixed in:
2.0.6

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database