Show-Hide / Collapse-Expand [show-hidecollapse-expand] < 1.3.0
unknown
[en] The Show-Hide / Collapse-Expand WordPress plugin before 1.3.0 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege us...
- Affected:
- up to 1.3.0
- Fixed in:
- 1.3.0
- Disclosed:
- Feb 27, 2023
CVE-2022-4829 on NVD →
Show-Hide / Collapse-Expand <= 1.2.5 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode
medium
The Show-Hide / Collapse-Expand plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode in versions up to, and including, 1.2.5 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor...
- CVSS:
- 6.4
- Affected:
- up to 1.2.5
- Fixed in:
- 1.3.0
- Disclosed:
- Jan 4, 2023
CVE-2022-4829 on NVD →
Show-Hide / Collapse-Expand <= 1.2.6 - Missing Authorization
medium
The Show-Hide / Collapse-Expand plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the bg_show_hide_save_plugin_settings() function called via and admin_post hook in versions up to, and including, 1.2.6. This makes it possible for authenticated attackers with minimal permiss...
- CVSS:
- 5.4
- Affected:
- up to 1.2.6
- Fixed in:
- 1.3.0
- Disclosed:
- Jan 4, 2023
Show-Hide / Collapse-Expand [show-hidecollapse-expand] < 1.3.0
unknown
The Show-Hide / Collapse-Expand plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the bg_show_hide_save_plugin_settings() function called via and admin_post hook in versions up to, and including, 1.2.6. This makes it possible for authenticated attackers with minimal permiss...
- Affected:
- up to 1.3.0
- Fixed in:
- 1.3.0
- Disclosed:
- Jan 4, 2023
Show-Hide / Collapse-Expand [show-hidecollapse-expand] < 1.3.0
unknown
No patched version available.
An unknown person discovered and reported this Broken Authentication vulnerability in WordPress Show-Hide / Collapse-Expand Plugin. This can be abused by a malicious actor to perform action which normally should only be able to be executed by higher privileged users. These actions might al...
- Affected:
- up to 1.3.0
- Fixed in:
- 1.3.0
- Disclosed:
- Jan 4, 2023
Show-Hide / Collapse-Expand [show-hidecollapse-expand] <= 1.2.5 (unfixed)
unknown
The plugin does not have authorisation check when updating its settings, which could allow any authenticated users, such as subscriber to update them. Furthermore, due to the lack of CSRF check, the issue is also exploitable via CSRF
- Affected:
- up to 1.2.5
- Fix:
- No patched version reported
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database