plugin

Types Vulnerabilities

8 known security issues reported for the Types WordPress plugin. Most recent disclosed Mar 26, 2024.

2 high 1 medium

Running Types on your site? Check whether your installed version is affected.

Scan your site free

Toolset Types – Custom Post Types, Custom Fields and Taxonomies [types] < 3.4.18

unknown

[en] Unrestricted Upload of File with Dangerous Type vulnerability in OnTheGoSystems Types.This issue affects Types: from n/a through 3.4.17.

Affected:
up to 3.4.18
Fixed in:
3.4.18
Disclosed:
Mar 26, 2024

CVE-2023-27440 on NVD →

Types <= 3.4.17 - Authenticated (Administrator+) Arbitrary File Upload

high

The Types plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in an unknown function in versions up to, and including, 3.4.17. This makes it possible for attackers, with administrator-level access, to upload arbitrary files on the affected site's server which may make remote...

CVSS:
7.2
Affected:
up to 3.4.17
Fixed in:
3.4.18
Disclosed:
Mar 3, 2023

CVE-2023-27440 on NVD →

Toolset Types < 1.8.8 - Cross-Site Scripting

high

The Toolset Types plugin plugin for WordPress is vulnerable to Cross-Site Scripting in versions before 1.8.8 due to insufficient input sanitization and output escaping. This makes it possible for attackers to inject arbitrary web scripts that execute in a victim's browser.

CVSS:
7.2
Affected:
up to 1.8.7.2
Fixed in:
1.8.8
Disclosed:
Nov 10, 2015

Toolset Types – Custom Post Types, Custom Fields and Taxonomies [types] < 1.8.8 (closed)

unknown

Because of this vulnerability, the attackers can inject arbitrary web script or HTML. Update the plugin.

Affected:
up to 1.8.8
Fixed in:
1.8.8
Disclosed:
Nov 10, 2015

Toolset Types – Custom Post Types, Custom Fields and Taxonomies [types] < 1.8.8

unknown

The Toolset Types plugin plugin for WordPress is vulnerable to Cross-Site Scripting in versions before 1.8.8 due to insufficient input sanitization and output escaping. This makes it possible for attackers to inject arbitrary web scripts that execute in a victim's browser.

Affected:
up to 1.8.8
Fixed in:
1.8.8
Disclosed:
Nov 10, 2015

Toolset Types <= 1.2.1.1 - Cross-Site Scripting

medium

The Toolset Types plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including, 1.2.1.1 due to insufficient input sanitization and output escaping. This makes it possible for attackers to inject arbitrary web scripts that execute in a victim's browser.

CVSS:
5.3
Affected:
up to 1.2.1.1
Fixed in:
1.2.1.2
Disclosed:
Apr 4, 2013

Toolset Types – Custom Post Types, Custom Fields and Taxonomies [types] < 1.2.1.2

unknown

The Toolset Types plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including, 1.2.1.1 due to insufficient input sanitization and output escaping. This makes it possible for attackers to inject arbitrary web scripts that execute in a victim's browser.

Affected:
up to 1.2.1.2
Fixed in:
1.2.1.2
Disclosed:
Apr 4, 2013

Toolset Types – Custom Post Types, Custom Fields and Taxonomies [types] < 1.8.8 (closed)

unknown
Affected:
up to 1.8.8
Fixed in:
1.8.8

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database