Radio Buttons for Taxonomies [radio-buttons-for-taxonomies] < 2.0.6
unknown
[en] The Radio Buttons for Taxonomies plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.0.5. This is due to missing or incorrect nonce validation on the save_single_term() function. This makes it possible for unauthenticated attackers to save terms via a forged request...
- Affected:
- up to 2.0.6
- Fixed in:
- 2.0.6
- Disclosed:
- Jul 1, 2023
CVE-2020-36740 on NVD →
Radio Buttons for Taxonomies [radio-buttons-for-taxonomies] < 2.0.6
unknown
- Affected:
- up to 2.0.6
- Fixed in:
- 2.0.6
- Disclosed:
- Jun 7, 2023
CVE-2021-4342 on NVD →
Radio Buttons for Taxonomies <= 2.0.5 - Cross-Site Request Forgery Bypass
medium
The Radio Buttons for Taxonomies plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.0.5. This is due to missing or incorrect nonce validation on the save_single_term() function. This makes it possible for unauthenticated attackers to save terms via a forged request gran...
- CVSS:
- 4.3
- Affected:
- up to 2.0.6
- Fixed in:
- 2.0.6
- Disclosed:
- Sep 16, 2020
CVE-2020-36740 on NVD →
Radio Buttons for Taxonomies [radio-buttons-for-taxonomies] < 2.0.6
unknown
Cross-Site Request Forgery (CSRF) vulnerability found by Jerome Bruandet (NinTechNet) in WordPress Radio Buttons for Taxonomies plugin (versions <= 2.0.5).
- Affected:
- up to 2.0.6
- Fixed in:
- 2.0.6
- Disclosed:
- Sep 16, 2020
Radio Buttons for Taxonomies [radio-buttons-for-taxonomies] < 2.0.6
unknown
NinTechNet discovered multiple WordPress plugins and themes vulnerable to Cross-Site Request Forgery (CSRF).
The items only check the CSRF nonce if it has been provided, making them vulnerable to CSRF attacks if the nonce is removed. This is due to the confusing use of logic operators when verifying the nonces.
- Affected:
- up to 2.0.6
- Fixed in:
- 2.0.6
Radio Buttons for Taxonomies [radio-buttons-for-taxonomies] < 2.0.6
unknown
Over 70 plugins and themes were vulnerable to Cross-Site Request Forgery due to improperly implemented nonce protection that could be bypassed.
- Affected:
- up to 2.0.6
- Fixed in:
- 2.0.6
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database