Subscribe to Category [subscribe-to-category] <= 2.7.3 (unfixed + closed)
unknown
[en] Missing Authorization vulnerability in Daniel Söderström / Sidney van de Stouwe Subscribe to Category allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Subscribe to Category: from n/a through 2.7.4.
- Affected:
- up to 2.7.3
- Fix:
- No patched version reported
- Disclosed:
- Jan 2, 2025
CVE-2022-43476 on NVD →
Subscribe to Category [subscribe-to-category] <= 2.7.4 (unfixed + closed)
unknown
[en] Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Daniel Söderström / Sidney van de Stouwe Subscribe to Category.This issue affects Subscribe to Category: from n/a through 2.7.4.
- Affected:
- up to 2.7.4
- Fix:
- No patched version reported
- Disclosed:
- Dec 20, 2023
CVE-2023-32590 on NVD →
Subscribe to Category [subscribe-to-category] <= 2.7.4 (unfixed + closed)
unknown
[en] Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Daniel Söderström / Sidney van de Stouwe Subscribe to Category allows SQL Injection.This issue affects Subscribe to Category: from n/a through 2.7.4.
- Affected:
- up to 2.7.4
- Fix:
- No patched version reported
- Disclosed:
- Nov 6, 2023
CVE-2023-38382 on NVD →
Subscribe to Category <= 2.7.4 - Unauthenticated SQL Injection
critical
The Subscribe to Category plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 2.7.4 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL q...
- CVSS:
- 9.8
- Affected:
- up to 2.7.4
- Fix:
- No patched version reported
- Disclosed:
- Jul 20, 2023
CVE-2023-32590 on NVD →
Subscribe to Category <= 2.7.3 - Missing Authorization
medium
The Subscribe to Category plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on its AJAX actions in versions up to, and including, 2.7.3. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to invoke them leading to Information Expos...
- CVSS:
- 5.4
- Affected:
- up to 2.7.3
- Fix:
- No patched version reported
- Disclosed:
- Oct 31, 2022
CVE-2022-43476 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database