plugin

Sermon Browser Vulnerabilities

11 known security issues reported for the Sermon Browser WordPress plugin. Most recent disclosed Mar 28, 2022.

1 critical 1 high 2 medium

Running Sermon Browser on your site? Check whether your installed version is affected.

Scan your site free

Sermon Browser [sermon-browser] <= 0.45.22 (unfixed + closed)

unknown

[en] The Sermon Browser WordPress plugin through 0.45.22 does not have CSRF checks in place when uploading Sermon files, and does not validate them in any way, allowing attackers to make a logged in admin upload arbitrary files such as PHP ones.

Affected:
up to 0.45.22
Fix:
No patched version reported
Disclosed:
Mar 28, 2022

CVE-2022-0499 on NVD →

Sermon Browser <= 0.45.22 - Cross-Site Request Forgery

high

The Sermon Browser WordPress plugin through 0.45.22 does not have CSRF checks in place when uploading Sermon files, and does not validate them in any way, allowing attackers to make a logged in admin upload arbitrary files such as PHP ones.

CVSS:
8.8
Affected:
up to 0.45.22
Fix:
No patched version reported
Disclosed:
Mar 1, 2022

CVE-2022-0499 on NVD →

Sermon Browser [sermon-browser] < 0.45.16 (closed)

unknown

[en] The sermon-browser plugin before 0.45.16 for WordPress has multiple XSS issues.

Affected:
up to 0.45.16
Fixed in:
0.45.16
Disclosed:
Aug 21, 2019

CVE-2016-10897 on NVD →

Sermon Browser <= 0.45.15 - Multiple Cross-Site Scripting

medium

The Sermon Browser plugin for WordPress is vulnerable to multiple Cross-Site Scripting in versions up to, and including, 0.45.15 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts that execute in a victim's browser.

CVSS:
6.1
Affected:
up to 0.45.15
Fixed in:
0.45.16
Disclosed:
Apr 26, 2016

CVE-2016-10897 on NVD →

Sermon Browser < 0.43.6 - SQL Injection

critical

The Sermon Browser plugin for WordPress is vulnerable to SQL Injection via the ‘sermon_id’ parameter in versions before 0.43.6 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append addition...

CVSS:
9.8
Affected:
up to 0.43.6
Fixed in:
0.43.6
Disclosed:
Apr 26, 2011

Sermon Browser < 0.43.6 - Cross-Site Scripting

medium

The Sermon Browser plugin for WordPress is vulnerable to Cross-Site Scripting via the 'file_name' parameter in versions before 0.43.6 due to insufficient input sanitization and output escaping. This makes it possible for attackers to inject arbitrary web scripts that execute in a victim's browser.

CVSS:
6.1
Affected:
up to 0.43.6
Fixed in:
0.43.6
Disclosed:
Apr 26, 2011

Sermon Browser [sermon-browser] < 0.44 (closed)

unknown

Sermon Browser plugin is prone to an SQL injection. This vulnerability allows an attacker to modify data, alter queries to the application SQL database, compromise the access and application or exploit hidden vulnerabilities in the underlying database.

Affected:
up to 0.44
Fixed in:
0.44
Disclosed:
Apr 26, 2011

Sermon Browser [sermon-browser] < 0.44 (closed)

unknown

There are several vulnerabilities in this plugin. The first is a cross-site scripting vulnerability and the second is an SQL injection vulnerability. These issues allow an attacker to steal cookie-based authentication credentials, modify data, or compromise the access.

Affected:
up to 0.44
Fixed in:
0.44
Disclosed:
Apr 26, 2011

Sermon Browser [sermon-browser] < 0.43.6

unknown

The Sermon Browser plugin for WordPress is vulnerable to Cross-Site Scripting via the 'file_name' parameter in versions before 0.43.6 due to insufficient input sanitization and output escaping. This makes it possible for attackers to inject arbitrary web scripts that execute in a victim's browser.

Affected:
up to 0.43.6
Fixed in:
0.43.6
Disclosed:
Apr 26, 2011

Sermon Browser [sermon-browser] < 0.43.6

unknown

The Sermon Browser plugin for WordPress is vulnerable to SQL Injection via the ‘sermon_id’ parameter in versions before 0.43.6 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append addition...

Affected:
up to 0.43.6
Fixed in:
0.43.6
Disclosed:
Apr 26, 2011

Sermon Browser [sermon-browser] < 0.43.6

unknown

The Sermon Browser WordPress plugin was affected by a SQL Injection security vulnerability.

Affected:
up to 0.43.6
Fixed in:
0.43.6

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database