Software License Manager <= 4.5.0 - Cross-Site Request Forgery leading to Arbitrary Domain Deletion
medium
The Software License Manager plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 4.5.0. This is due to missing or incorrect nonce validation on the del_reistered_domains AJAX action. This makes it possible for unauthenticated attackers to delete an entry in the plugin's re...
- CVSS:
- 4.3
- Affected:
- up to 4.5.1
- Fixed in:
- 4.5.1
- Disclosed:
- Sep 13, 2021
CVE-2021-24711 on NVD →
Software License Manager <= 4.4.9 - Authenticated (Admin+) Stored Cross-Site Scripting
medium
The Software License Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the License Key Prefix setting in versions up to, and including, 4.4.9 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrative privileges, to inj...
- CVSS:
- 5.5
- Affected:
- up to 4.4.9
- Fixed in:
- 4.5.0
- Disclosed:
- Aug 31, 2021
Software License Manager <= 4.4.7 - Reflected Cross-Site Scripting
medium
The Software License Manager WordPress plugin before 4.4.8 does not sanitise or escape the edit_record parameter before outputting it back in the page in the admin dashboard, leading to a Reflected Cross-Site Scripting issue
- CVSS:
- 6.1
- Affected:
- up to 4.4.8
- Fixed in:
- 4.4.8
- Disclosed:
- Aug 11, 2021
CVE-2021-24560 on NVD →
Software License Manager < 4.4.6 - Cross-Site Request Forgery
high
Cross-site request forgery (CSRF) vulnerability in Software License Manager versions prior to 4.4.6 allows remote attackers to hijack the authentication of administrators via unspecified vectors.
- CVSS:
- 8.8
- Affected:
- up to 4.4.6
- Fixed in:
- 4.4.6
- Disclosed:
- Jul 8, 2021
CVE-2021-20782 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database