plugin

Wp Abstracts Manuscripts Manager Vulnerabilities

9 known security issues reported for the Wp Abstracts Manuscripts Manager WordPress plugin. Most recent disclosed Sep 3, 2025.

2 high 7 medium

Running Wp Abstracts Manuscripts Manager on your site? Check whether your installed version is affected.

Scan your site free

Abstracts <= 2.7.4 - Unauthenticated Local File Inclusion

high

The Abstracts plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 2.7.4. This makes it possible for unauthenticated attackers to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls,...

CVSS:
8.1
Affected:
up to 2.7.4
Fixed in:
2.7.5
Disclosed:
Sep 3, 2025

CVE-2025-48338 on NVD →

WP Abstracts <= 2.7.4 - Cross-Site Request Forgery to Stored Cross-Site Scripting

medium

The WP Abstracts plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.7.4. This is due to missing or incorrect nonce validation on a function. This makes it possible for unauthenticated attackers to update settings and inject malicious web scripts via a forged request...

CVSS:
6.1
Affected:
up to 2.7.4
Fix:
No patched version reported
Disclosed:
Apr 9, 2025

CVE-2025-32591 on NVD →

WP Abstracts <= 2.7.3 - Cross-Site Request Forgery to Arbitrary Account Deletion

high

The WP Abstracts plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.7.3. This is due to missing nonce validation on multiple functions. This makes it possible for unauthenticated attackers to delete arbitrary accounts via a forged request granted they can trick a si...

CVSS:
8.1
Affected:
up to 2.7.3
Fixed in:
2.7.4
Disclosed:
Feb 11, 2025

CVE-2024-12386 on NVD →

WP Abstracts <= 2.7.2 - Cross-Site Request Forgery to Reflected Cross-Site Scripting

medium

The WP Abstracts plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.7.2. This is due to missing nonce validation on the wpabstracts_load_status() and wpabstracts_delete_abstracts() functions. This makes it possible for unauthenticated attackers to inject malicious w...

CVSS:
6.1
Affected:
up to 2.7.2
Fixed in:
2.7.3
Disclosed:
Jan 17, 2025

CVE-2024-12385 on NVD →

WP Abstracts <= 2.7.1 - Authenticated (Administrator+) Stored Cross-Site Scripting

medium

The WP Abstracts plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.7.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level access and above, to inject arbitrary web scripts in pages t...

CVSS:
4.4
Affected:
up to 2.7.1
Fixed in:
2.7.2
Disclosed:
Oct 24, 2024

CVE-2024-50411 on NVD →

WP Abstracts <= 2.6.5 - Authenticated (Administrator+) Stored Cross-Site Scripting

medium

The WP Abstracts plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.6.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level access and above, to inject arbitrary web scripts in pages t...

CVSS:
4.4
Affected:
up to 2.6.5
Fixed in:
2.7.0
Disclosed:
Sep 23, 2024

CVE-2024-44045 on NVD →

WP Abstracts <= 2.6.2 - Authenticated (Administrator+) Stored Cross-Site Scripting

medium

The WP Abstracts plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versions up to, and including, 2.6.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrar...

CVSS:
4.4
Affected:
up to 2.6.2
Fixed in:
2.6.3
Disclosed:
Jun 27, 2023

CVE-2023-28692 on NVD →

WP Abstracts <= 2.6.2 - Cross-Site Request Forgery

medium

The WP Abstracts plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.6.2. This is due to missing or incorrect nonce validation on one of its functions. This makes it possible for unauthenticated attackers to invoke this function via a forged request granted they can tric...

CVSS:
4.3
Affected:
up to 2.6.2
Fixed in:
2.6.3
Disclosed:
Jun 27, 2023

CVE-2023-36517 on NVD →

WP Abstracts <= 2.6.1 - Reflected Cross-Site Scripting

medium

The WP Abstracts plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'login' and 'key' parameters in versions up to, and including, 2.6.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages tha...

CVSS:
6.1
Affected:
up to 2.6.1
Fixed in:
2.6.2
Disclosed:
May 8, 2023

CVE-2023-29385 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database