WordPress Sentinel <= 1.0.0 - Cross-Site Request Forgery
high
Cross-site request forgery (CSRF) vulnerability in wordpress_sentinel.php in the Sentinel plugin 1.0.0 for WordPress allows remote attackers to hijack the authentication of an administrator for requests that trigger snapshots.
The WordPress Sentinel plugin for WordPress is vulnerable to Cross-Site Request Forgery i...
- CVSS:
- 8.8
- Affected:
- up to 1.0.0
- Fixed in:
- 1.0.1
- Disclosed:
- Dec 16, 2011
CVE-2011-5226 on NVD →
WordPress Sentinel < 1.0.1 - SQL Injection
critical
SQL injection vulnerability in the Sentinel plugin 1.0.0 for WordPress allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
- CVSS:
- 9.8
- Affected:
- up to 1.0.0
- Fixed in:
- 1.0.1
- Disclosed:
- Dec 14, 2011
CVE-2011-5224 on NVD →
WordPress Sentinel <= 1.0.0 - Cross-Site Scripting
medium
Cross-site scripting (XSS) vulnerability in wordpress_sentinel.php in the Sentinel plugin 1.0.0 for WordPress allows remote attackers to inject arbitrary web script or HTML via unknown vectors.
- CVSS:
- 6.1
- Affected:
- up to 1.0.0
- Fixed in:
- 1.0.1
- Disclosed:
- Dec 14, 2011
CVE-2011-5225 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database