Seraphinite Post .DOCX Source [seraphinite-post-docx-source] < 2.16.10
unknown
[en] Missing Authorization vulnerability in Seraphinite Solutions Seraphinite Post .DOCX Source allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Seraphinite Post .DOCX Source: from n/a through 2.16.9.
- Affected:
- up to 2.16.10
- Fixed in:
- 2.16.10
- Disclosed:
- Nov 1, 2024
CVE-2024-38727 on NVD →
Seraphinite Post .DOCX Source [seraphinite-post-docx-source] < 2.16.10
unknown
[en] Server-Side Request Forgery (SSRF) vulnerability in Seraphinite Solutions Seraphinite Post .DOCX Source.This issue affects Seraphinite Post .DOCX Source: from n/a through 2.16.9.
- Affected:
- up to 2.16.10
- Fixed in:
- 2.16.10
- Disclosed:
- Jul 22, 2024
CVE-2024-38728 on NVD →
Seraphinite Post .DOCX Source <= 2.16.9 - Authenticated (Subscriber+) Server-Side Request Forgery
medium
The Seraphinite Post .DOCX Source plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 2.16.9. This makes it possible for authenticated attackers, with Subscriber-level access and above, to make web requests to arbitrary locations originating from the web application w...
- CVSS:
- 6.4
- Affected:
- up to 2.16.9
- Fixed in:
- 2.16.10
- Disclosed:
- Jul 11, 2024
CVE-2024-38728 on NVD →
Seraphinite Post .DOCX Source <= 2.16.9 - Missing Authorization
medium
The Seraphinite Post .DOCX Source plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 2.16.9. This makes it possible for authenticated attackers, with Subscriber-level access and above, to perform an unauthorized action.
- CVSS:
- 4.3
- Affected:
- up to 2.16.9
- Fixed in:
- 2.16.10
- Disclosed:
- Jul 11, 2024
CVE-2024-38727 on NVD →
Seraphinite Post .DOCX Source [seraphinite-post-docx-source] < 2.16.7
unknown
[en] Cross-Site Request Forgery (CSRF) vulnerability in Seraphinite Solutions Seraphinite Post .DOCX Source allows Cross Site Request Forgery.This issue affects Seraphinite Post .DOCX Source: from n/a through 2.16.6.
- Affected:
- up to 2.16.7
- Fixed in:
- 2.16.7
- Disclosed:
- Nov 30, 2023
CVE-2023-48279 on NVD →
Seraphinite Post .DOCX Source <= 2.16.6 - Cross-Site Request Forgery
medium
The Seraphinite Post .DOCX Source plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.16.6. This is due to missing or incorrect nonce validation on the saveSettings functionality. This makes it possible for unauthenticated attackers to update the plugins settings via a f...
- CVSS:
- 4.3
- Affected:
- up to 2.16.6
- Fixed in:
- 2.16.7
- Disclosed:
- Nov 23, 2023
CVE-2023-48279 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database