Related Posts for WordPress <= 2.2.1 - Cross-Site Request Forgery
medium
The Related Posts for WordPress plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.2.1. This is due to missing or incorrect nonce validation on the handle_create_link() function. This makes it possible for unauthenticated attackers to add related posts to other post...
- CVSS:
- 5.4
- Affected:
- up to 2.2.1
- Fixed in:
- 2.2.2
- Disclosed:
- Mar 13, 2024
CVE-2024-0592 on NVD →
Related Posts for WordPress [related-posts-for-wp] < 2.2.2
unknown
[en] The Related Posts for WordPress plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.2.1. This is due to missing or incorrect nonce validation on the handle_create_link() function. This makes it possible for unauthenticated attackers to add related posts to other...
- Affected:
- up to 2.2.2
- Fixed in:
- 2.2.2
- Disclosed:
- Mar 13, 2024
CVE-2024-0592 on NVD →
Related Posts for WordPress <= 2.1.2 - Authenticated (Administrator+) Stored Cross-Site Scripting
medium
The Related Posts for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘heading_text’ parameter in versions up to, and including, 2.1.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions...
- CVSS:
- 5.5
- Affected:
- up to 2.1.2
- Fixed in:
- 2.1.3
- Disclosed:
- Oct 24, 2022
CVE-2022-3506 on NVD →
Related Posts for WordPress [related-posts-for-wp] < 2.1.3
unknown
[en] Cross-site Scripting (XSS) - Stored in GitHub repository barrykooij/related-posts-for-wp prior to 2.1.3.
- Affected:
- up to 2.1.3
- Fixed in:
- 2.1.3
- Disclosed:
- Oct 14, 2022
CVE-2022-3506 on NVD →
Related Posts for WordPress <= 2.1.1 - Reflected Cross-Site Scripting
medium
The Related Posts for WordPress plugin is vulnerable to Reflected Cross-Site Scripting due to the use of unsanitized user input when constructing a URL in versions up to, and including, 2.1.1. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successf...
- CVSS:
- 6.1
- Affected:
- up to 2.1.1
- Fixed in:
- 2.1.2
- Disclosed:
- Oct 3, 2022
Related Posts for WordPress [related-posts-for-wp] < 2.1.2
unknown
The Related Posts for WordPress plugin is vulnerable to Reflected Cross-Site Scripting due to the use of unsanitized user input when constructing a URL in versions up to, and including, 2.1.1. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successf...
- Affected:
- up to 2.1.2
- Fixed in:
- 2.1.2
- Disclosed:
- Oct 3, 2022
Related Posts for WordPress [related-posts-for-wp] < 2.0.5
unknown
[en] The Related Posts for WordPress plugin through 2.0.4 does not sanitise its heading_text and CSS settings, allowing high privilege users (admin) to set XSS payloads in them, leading to Stored Cross-Site Scripting issues.
- Affected:
- up to 2.0.5
- Fixed in:
- 2.0.5
- Disclosed:
- Jul 19, 2021
CVE-2021-24482 on NVD →
Related Posts for WordPress <= 2.0.4 - Stored Cross-Site Scripting
medium
The Related Posts for WordPress plugin through 2.0.4 does not sanitise its heading_text and CSS settings, allowing high privilege users (admin) to set XSS payloads in them, leading to Stored Cross-Site Scripting issues.
- CVSS:
- 5.5
- Affected:
- up to 2.0.4
- Fixed in:
- 2.0.5
- Disclosed:
- May 17, 2021
CVE-2021-24482 on NVD →
Related Posts for WordPress [related-posts-for-wp] < 2.0.4
unknown
[en] Unvalidated input and lack of output encoding within the Related Posts for WordPress plugin before 2.0.4 lead to a Reflected Cross-Site Scripting (XSS) vulnerability within the 'lang' GET parameter while editing a post, triggered when users with the capability of editing posts access a malicious URL.
- Affected:
- up to 2.0.4
- Fixed in:
- 2.0.4
- Disclosed:
- Apr 5, 2021
CVE-2021-24180 on NVD →
Related Posts for WordPress <= 2.0.3 - Reflected Cross-Site Scripting
medium
Unvalidated input and lack of output encoding within the Related Posts for WordPress plugin before 2.0.4 lead to a Reflected Cross-Site Scripting (XSS) vulnerability within the 'lang' GET parameter while editing a post, triggered when users with the capability of editing posts access a malicious URL.
- CVSS:
- 5.4
- Affected:
- up to 2.0.3
- Fixed in:
- 2.0.4
- Disclosed:
- Mar 15, 2021
CVE-2021-24180 on NVD →
Related Posts for WordPress < 1.8.2 - Reflected Cross-Site Scripting
medium
The Related Posts for WordPress plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, not including, 1.8.2 due to insufficient input sanitization and output escaping. The same vulnerability exists in Related Posts Premium up to, not including, 1.3.4. This makes it possible for attackers to injec...
- CVSS:
- 6.1
- Affected:
- up to 1.8.2
- Fixed in:
- 1.8.2
- Disclosed:
- Apr 20, 2015
Related Posts for WordPress [related-posts-for-wp] < 1.8.2
unknown
Cross-Site Scripting (XSS) vulnerability discovered by Barry Kooij in WordPress Related Posts for WordPress plugin (versions <= 1.8.1).
Update the WordPress Related Posts for WordPress plugin to the latest available version (at least 1.8.2).
- Affected:
- up to 1.8.2
- Fixed in:
- 1.8.2
- Disclosed:
- Apr 20, 2015
Related Posts for WordPress [related-posts-for-wp] < 1.8.2
unknown
The Related Posts for WordPress plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, not including, 1.8.2 due to insufficient input sanitization and output escaping. The same vulnerability exists in Related Posts Premium up to, not including, 1.3.4. This makes it possible for attackers to injec...
- Affected:
- up to 1.8.2
- Fixed in:
- 1.8.2
- Disclosed:
- Apr 20, 2015
Related Posts for WordPress [related-posts-for-wp] < 1.8.2
unknown
The Related Posts for WordPress WordPress plugin was affected by a Cross-Site Scripting (XSS) security vulnerability.
- Affected:
- up to 1.8.2
- Fixed in:
- 1.8.2
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database