plugin

Wordpress Exit Box Lite Vulnerabilities

4 known security issues reported for the Wordpress Exit Box Lite WordPress plugin. Most recent disclosed Jun 5, 2023.

2 medium

Running Wordpress Exit Box Lite on your site? Check whether your installed version is affected.

Scan your site free

WordPress Exit Box Lite [wordpress-exit-box-lite] < 1.10 (closed)

unknown

[en] A vulnerability classified as problematic was found in Exit Box Lite Plugin up to 1.06 on WordPress. Affected by this vulnerability is the function exitboxadmin of the file wordpress-exit-box-lite.php. The manipulation leads to cross-site request forgery. The attack can be launched remotely. Upgrading to version 1...

Affected:
up to 1.10
Fixed in:
1.10
Disclosed:
Jun 5, 2023

CVE-2013-10029 on NVD →

WordPress Exit Box Lite [wordpress-exit-box-lite] < 1.10 (closed)

unknown

[en] A vulnerability, which was classified as problematic, has been found in Exit Box Lite Plugin up to 1.06 on WordPress. Affected by this issue is some unknown functionality of the file wordpress-exit-box-lite.php. The manipulation leads to information disclosure. The attack may be launched remotely. Upgrading to ver...

Affected:
up to 1.10
Fixed in:
1.10
Disclosed:
Jun 5, 2023

CVE-2013-10030 on NVD →

WordPress Exit Box Lite <= 1.06 - Full Path Dislcosure

medium

The WordPress Exit Box Lite plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 1.06 via the /wordpress-exit-box-lite.php file. This can allow unauthenticated attackers to obtain the full path of the targeted WordPress website by directly accessing the file.

CVSS:
5.3
Affected:
1.06 – 1.06
Fixed in:
1.10
Disclosed:
May 28, 2013

CVE-2013-10030 on NVD →

WordPress Exit Box Lite <= 1.0.6 - Cross-Site Request Forgery

medium

The WordPress Exit Box Lite plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.06. This is due to missing or incorrect nonce validation on the exit_box_admin() function. This makes it possible for unauthenticated attackers to modify the plugin's settings via a forged re...

CVSS:
4.3
Affected:
up to 1.06
Fixed in:
1.10
Disclosed:
May 28, 2013

CVE-2013-10029 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database