plugin

Sydney Toolbox Vulnerabilities

10 known security issues reported for the Sydney Toolbox WordPress plugin. Most recent disclosed May 14, 2024.

5 medium

Running Sydney Toolbox on your site? Check whether your installed version is affected.

Scan your site free

Sydney Toolbox [sydney-toolbox] < 1.32

unknown

[en] The Sydney Toolbox plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the "aThemes: Portfolio" widget in all versions up to, and including, 1.31 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contri...

Affected:
up to 1.32
Fixed in:
1.32
Disclosed:
May 14, 2024

CVE-2024-4473 on NVD →

Sydney Toolbox <= 1.31 - Authenticated (Contributor+) Stored Cross-Site Scripting via aThemes: Portfolio Widget

medium

The Sydney Toolbox plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the "aThemes: Portfolio" widget in all versions up to, and including, 1.31 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor...

CVSS:
6.4
Affected:
up to 1.31
Fixed in:
1.32
Disclosed:
May 13, 2024

CVE-2024-4473 on NVD →

Sydney Toolbox [sydney-toolbox] < 1.31

unknown

[en] The Sydney Toolbox plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the style parameter in all versions up to, and including, 1.30 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor access and above, to inject arbitr...

Affected:
up to 1.31
Fixed in:
1.31
Disclosed:
May 2, 2024

CVE-2024-4036 on NVD →

Sydney Toolbox <= 1.30 - Authenticated (Contributor+) Stored Cross-Site Scripting

medium

The Sydney Toolbox plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the style parameter in all versions up to, and including, 1.30 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor access and above, to inject arbitrary w...

CVSS:
6.4
Affected:
up to 1.30
Fixed in:
1.31
Disclosed:
May 1, 2024

CVE-2024-4036 on NVD →

Sydney Toolbox [sydney-toolbox] < 1.29

unknown

[en] The Sydney Toolbox plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Filterable Gallery widget in all versions up to, and including, 1.28 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with...

Affected:
up to 1.29
Fixed in:
1.29
Disclosed:
Apr 9, 2024

CVE-2024-3208 on NVD →

Sydney Toolbox <= 1.28 - Authenticated (Contributor+) Stored Cross-Site Scripting via Filterable Gallery

medium

The Sydney Toolbox plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Filterable Gallery widget in all versions up to, and including, 1.28 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with cont...

CVSS:
6.4
Affected:
up to 1.28
Fixed in:
1.29
Disclosed:
Apr 5, 2024

CVE-2024-3208 on NVD →

Sydney Toolbox [sydney-toolbox] < 1.27

unknown

[en] The Sydney Toolbox plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the _id attribute of widgets in all versions up to, and including, 1.26 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contribut...

Affected:
up to 1.27
Fixed in:
1.27
Disclosed:
Mar 29, 2024

CVE-2024-2936 on NVD →

Sydney Toolbox <= 1.26 - Authenticated (Contributor+) Stored Cross-Site Scripting via _id

medium

The Sydney Toolbox plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the _id attribute of widgets in all versions up to, and including, 1.26 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-le...

CVSS:
6.4
Affected:
up to 1.26
Fixed in:
1.27
Disclosed:
Mar 28, 2024

CVE-2024-2936 on NVD →

Sydney Toolbox [sydney-toolbox] < 1.26

unknown

[en] The Sydney Toolbox plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's aThemes Slider button element in all versions up to, and including, 1.25 due to insufficient input sanitization and output escaping on user supplied link. This makes it possible for authenticated attackers with co...

Affected:
up to 1.26
Fixed in:
1.26
Disclosed:
Feb 20, 2024

CVE-2024-1447 on NVD →

Sydney Toolbox <= 1.25 - Authenticated (Contributor+) Stored Cross-Site Scripting

medium

The Sydney Toolbox plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's aThemes Slider button element in all versions up to, and including, 1.25 due to insufficient input sanitization and output escaping on user supplied link. This makes it possible for authenticated attackers with contrib...

CVSS:
6.4
Affected:
up to 1.25
Fixed in:
1.26
Disclosed:
Feb 14, 2024

CVE-2024-1447 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database