Toolset Types – Custom Post Types, Custom Fields and Taxonomies [types] < 3.4.18
unknown
[en] Unrestricted Upload of File with Dangerous Type vulnerability in OnTheGoSystems Types.This issue affects Types: from n/a through 3.4.17.
- Affected:
- up to 3.4.18
- Fixed in:
- 3.4.18
- Disclosed:
- Mar 26, 2024
CVE-2023-27440 on NVD →
Types <= 3.4.17 - Authenticated (Administrator+) Arbitrary File Upload
high
The Types plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in an unknown function in versions up to, and including, 3.4.17. This makes it possible for attackers, with administrator-level access, to upload arbitrary files on the affected site's server which may make remote...
- CVSS:
- 7.2
- Affected:
- up to 3.4.17
- Fixed in:
- 3.4.18
- Disclosed:
- Mar 3, 2023
CVE-2023-27440 on NVD →
Toolset Types < 1.8.8 - Cross-Site Scripting
high
The Toolset Types plugin plugin for WordPress is vulnerable to Cross-Site Scripting in versions before 1.8.8 due to insufficient input sanitization and output escaping. This makes it possible for attackers to inject arbitrary web scripts that execute in a victim's browser.
- CVSS:
- 7.2
- Affected:
- up to 1.8.7.2
- Fixed in:
- 1.8.8
- Disclosed:
- Nov 10, 2015
Toolset Types – Custom Post Types, Custom Fields and Taxonomies [types] < 1.8.8 (closed)
unknown
Because of this vulnerability, the attackers can inject arbitrary web script or HTML.
Update the plugin.
- Affected:
- up to 1.8.8
- Fixed in:
- 1.8.8
- Disclosed:
- Nov 10, 2015
Toolset Types – Custom Post Types, Custom Fields and Taxonomies [types] < 1.8.8
unknown
The Toolset Types plugin plugin for WordPress is vulnerable to Cross-Site Scripting in versions before 1.8.8 due to insufficient input sanitization and output escaping. This makes it possible for attackers to inject arbitrary web scripts that execute in a victim's browser.
- Affected:
- up to 1.8.8
- Fixed in:
- 1.8.8
- Disclosed:
- Nov 10, 2015
Toolset Types <= 1.2.1.1 - Cross-Site Scripting
medium
The Toolset Types plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including, 1.2.1.1 due to insufficient input sanitization and output escaping. This makes it possible for attackers to inject arbitrary web scripts that execute in a victim's browser.
- CVSS:
- 5.3
- Affected:
- up to 1.2.1.1
- Fixed in:
- 1.2.1.2
- Disclosed:
- Apr 4, 2013
Toolset Types – Custom Post Types, Custom Fields and Taxonomies [types] < 1.2.1.2
unknown
The Toolset Types plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including, 1.2.1.1 due to insufficient input sanitization and output escaping. This makes it possible for attackers to inject arbitrary web scripts that execute in a victim's browser.
- Affected:
- up to 1.2.1.2
- Fixed in:
- 1.2.1.2
- Disclosed:
- Apr 4, 2013
Toolset Types – Custom Post Types, Custom Fields and Taxonomies [types] < 1.8.8 (closed)
unknown
- Affected:
- up to 1.8.8
- Fixed in:
- 1.8.8
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database