Simple Author Box [simple-author-box] < 2.52
unknown
[en] The Simple Author Box WordPress plugin before 2.52 does not verify a user ID before outputting information about that user, leading to arbitrary user information disclosure to users with a role as low as Contributor.
- Affected:
- up to 2.52
- Fixed in:
- 2.52
- Disclosed:
- Aug 14, 2023
CVE-2023-3601 on NVD →
Simple Author Box <= 2.51 - Authenticated (Contributor+) Insecure Direct Object Reference to Arbitrary User Sensitive Information Exposure
medium
The Simple Author Box plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and including, 2.51. This is due to missing validation on a user controlled key. This makes it possible for authenticated attackers, with contributor-level permissions and above, to expose sensitive user info...
- CVSS:
- 4.3
- Affected:
- up to 2.51
- Fixed in:
- 2.52
- Disclosed:
- Jul 24, 2023
CVE-2023-3601 on NVD →
Freemius SDK <= 2.5.9 - Reflected Cross-Site Scripting via fs_request_get
medium
The Freemius SDK for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘fs_request_get’ function in versions up to, and including, 2.5.9 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute...
- CVSS:
- 6.1
- Affected:
- up to 2.3.22
- Fixed in:
- 2.4
- Disclosed:
- Jul 18, 2023
CVE-2023-33999 on NVD →
Simple Author Box [simple-author-box] < 2.51
unknown
Update the WordPress Simple Author Box plugin to the latest available version (at least 2.51).
Unknown discovered and reported this Cross Site Request Forgery (CSRF) vulnerability in WordPress Simple Author Box Plugin. This could allow a malicious actor to force higher privileged users to execute unwanted actions under...
- Affected:
- up to 2.51
- Fixed in:
- 2.51
- Disclosed:
- Mar 29, 2023
Simple Author Box <= 2.50 - Cross-Site Request Forgery via save_user_profile
medium
The Simple Author Box plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.50. This is due to missing or incorrect nonce validation on the save_user_profile function. This makes it possible for unauthenticated attackers to edit user profile settings of other users via a f...
- CVSS:
- 4.3
- Affected:
- up to 2.50
- Fixed in:
- 2.51
- Disclosed:
- Mar 28, 2023
Simple Author Box [simple-author-box] < 2.51
unknown
The Simple Author Box plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.50. This is due to missing or incorrect nonce validation on the save_user_profile function. This makes it possible for unauthenticated attackers to edit user profile settings of other users via a f...
- Affected:
- up to 2.51
- Fixed in:
- 2.51
- Disclosed:
- Mar 28, 2023
Simple Author Box [simple-author-box] < 2.4
unknown
** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.
- Affected:
- up to 2.4
- Fixed in:
- 2.4
CVE-2023-33999 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database