Vision – Interactive Image Map Builder [vision] < 1.7.2
unknown
[en] Missing Authorization vulnerability in Avirtum Vision Interactive.This issue affects Vision Interactive: from n/a through 1.7.1.
- Affected:
- up to 1.7.2
- Fixed in:
- 1.7.2
- Disclosed:
- Jun 9, 2024
CVE-2024-32779 on NVD →
Vision Interactive <= 1.7.1 - Missing Authorization
medium
The Vision Interactive plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on a function in versions up to, and including, 1.7.1. This makes it possible for unauthenticated attackers to view deactivated items.
- CVSS:
- 5.3
- Affected:
- up to 1.7.1
- Fixed in:
- 1.7.2
- Disclosed:
- Apr 22, 2024
CVE-2024-32779 on NVD →
Vision – Interactive Image Map Builder [vision] < 1.5.4
unknown
[en] The Vision Interactive For WordPress plugin through 1.5.3 does not sanitise and escape some of its settings, which could allow users such as contributor+ to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.
- Affected:
- up to 1.5.4
- Fixed in:
- 1.5.4
- Disclosed:
- Jan 9, 2023
CVE-2022-4391 on NVD →
Vision Interactive <= 1.5.3 - Authenticated (Contributor+) Stored Cross-Site Scripting
medium
The Vision Interactive plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘shortcode’ function in versions up to, and including, 1.5.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level permissions and above, to i...
- CVSS:
- 6.4
- Affected:
- up to 1.5.3
- Fixed in:
- 1.5.4
- Disclosed:
- Dec 16, 2022
CVE-2022-4391 on NVD →
Vision Interactive For WordPress <= 1.5.1 - Reflected Cross-Site Scripting
medium
The "Vision Interactive For WordPress" plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘page’ parameter in versions up to, and including, 1.5.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in...
- CVSS:
- 6.1
- Affected:
- up to 1.5.1
- Fixed in:
- 1.5.2
- Disclosed:
- Oct 11, 2021
Vision – Interactive Image Map Builder [vision] < 1.5.2
unknown
Reflected Cross-Site Scripting vulnerability discovered by WPScanTeam in WordPress Vision Interactive plugin (versions <= 1.4.4).
- Affected:
- up to 1.5.2
- Fixed in:
- 1.5.2
- Disclosed:
- Oct 11, 2021
Vision – Interactive Image Map Builder [vision] < 1.5.2
unknown
The "Vision Interactive For WordPress" plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘page’ parameter in versions up to, and including, 1.5.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in...
- Affected:
- up to 1.5.2
- Fixed in:
- 1.5.2
- Disclosed:
- Oct 11, 2021
Vision – Interactive Image Map Builder [vision] < 1.5.2
unknown
Most plugins (both free and premium) from the Avirtum author do not escape a page parameter before outputting it back in attributes, leading to Reflected Cross-Site Scripting issues.
The issues were reported to the vendor on August 4th, 2021
- Affected:
- up to 1.5.2
- Fixed in:
- 1.5.2
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database