Starbox – the Author Box for Humans [starbox] < 3.5.3
unknown
[en] The Starbox WordPress plugin before 3.5.3 does not properly render social media profiles URLs in certain contexts, like the malicious user's profile or pages where the starbox shortcode is used, which may be abused by users with at least the contributor role to conduct Stored XSS attacks.
- Affected:
- up to 3.5.3
- Fixed in:
- 3.5.3
- Disclosed:
- Sep 30, 2024
CVE-2024-8239 on NVD →
Starbox – the Author Box for Humans [starbox] < 3.5.2
unknown
[en] The Starbox WordPress plugin before 3.5.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).
- Affected:
- up to 3.5.2
- Fixed in:
- 3.5.2
- Disclosed:
- Sep 10, 2024
CVE-2024-7955 on NVD →
Starbox <= 3.5.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via Twitter URL Field
medium
The Starbox – the Author Box for Humans plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Twitter URL field in all versions up to, and including, 3.5.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access an...
- CVSS:
- 6.4
- Affected:
- up to 3.5.2
- Fixed in:
- 3.5.3
- Disclosed:
- Sep 9, 2024
CVE-2024-8239 on NVD →
Starbox – the Author Box for Humans <= 3.5.1 - Authenticated (Admin+) Stored Cross-Site Scripting
medium
The Starbox – the Author Box for Humans plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 3.5.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions an...
- CVSS:
- 4.4
- Affected:
- up to 3.5.1
- Fixed in:
- 3.5.2
- Disclosed:
- Aug 20, 2024
CVE-2024-7955 on NVD →
Starbox – the Author Box for Humans [starbox] < 3.5.0
unknown
[en] The Starbox WordPress plugin before 3.5.0 does not sanitise and escape some parameters, which could allow users with a role as low as Contributor to perform Cross-Site Scripting attacks
- Affected:
- up to 3.5.0
- Fixed in:
- 3.5.0
- Disclosed:
- Mar 11, 2024
CVE-2024-1273 on NVD →
Starbox – the Author Box for Humans [starbox] < 3.5.0
unknown
[en] The Starbox plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Job Settings user profile fields in all versions up to, and including, 3.4.8 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with subscriber-level access and above,...
- Affected:
- up to 3.5.0
- Fixed in:
- 3.5.0
- Disclosed:
- Feb 20, 2024
CVE-2023-6806 on NVD →
Starbox <= 3.4.9 - Authenticated (Contributor+) Stored Cross-Site Scripting
medium
The Starbox – the Author Box for Humans plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 3.4.9 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access...
- CVSS:
- 6.4
- Affected:
- up to 3.4.9
- Fixed in:
- 3.5.0
- Disclosed:
- Feb 13, 2024
CVE-2024-1273 on NVD →
Starbox – the Author Box for Humans [starbox] < 3.5.0
unknown
[en] The Starbox plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Profile Display Name and Social Settings in all versions up to, and including, 3.4.8 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with subscriber-level access and...
- Affected:
- up to 3.5.0
- Fixed in:
- 3.5.0
- Disclosed:
- Feb 7, 2024
CVE-2024-0256 on NVD →
Starbox <= 3.4.8 - Authenticated (Subscriber+) Stored Cross-Site Scripting via Job Settings
medium
The Starbox plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Job Settings user profile fields in all versions up to, and including, 3.4.8 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with subscriber-level access and above, to in...
- CVSS:
- 6.4
- Affected:
- up to 3.4.8
- Fixed in:
- 3.5.0
- Disclosed:
- Feb 6, 2024
CVE-2023-6806 on NVD →
Starbox – the Author Box for Humans [starbox] < 3.4.8
unknown
[en] The Starbox – the Author Box for Humans plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 3.4.7 via the action function due to missing validation on a user controlled key. This makes it possible for subscribers to view plugin preferences and potentially ot...
- Affected:
- up to 3.4.8
- Fixed in:
- 3.4.8
- Disclosed:
- Feb 5, 2024
CVE-2024-0366 on NVD →
Starbox <= 3.4.8 - Authenticated (Subscriber+) Stored Cross-Site Scripting via Profile Display Name and Social Settings
medium
The Starbox plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Profile Display Name and Social Settings in all versions up to, and including, 3.4.8 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with subscriber-level access and abov...
- CVSS:
- 6.4
- Affected:
- up to 3.4.8
- Fixed in:
- 3.5.0
- Disclosed:
- Jan 31, 2024
CVE-2024-0256 on NVD →
Starbox – the Author Box for Humans <= 3.4.7 - Insecure Direct Object Reference
medium
The Starbox – the Author Box for Humans plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 3.4.7 via the action function due to missing validation on a user controlled key. This makes it possible for subscribers to view plugin preferences and potentially other u...
- CVSS:
- 4.3
- Affected:
- up to 3.4.7
- Fixed in:
- 3.4.8
- Disclosed:
- Jan 30, 2024
CVE-2024-0366 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database