WP Custom Cursors | WordPress Cursor Plugin [wp-custom-cursors] <= 3.3 (unfixed)
unknown
[en] The WP Custom Cursors | WordPress Cursor Plugin WordPress plugin through 3.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)
- Affected:
- up to 3.3
- Fix:
- No patched version reported
- Disclosed:
- Jan 8, 2024
CVE-2023-5911 on NVD →
WP Custom Cursors | WordPress Cursor Plugin [wp-custom-cursors] < 3.2
unknown
[en] Cross-Site Request Forgery (CSRF) vulnerability in Web_Trendy WP Custom Cursors | WordPress Cursor Plugin plugin < 3.2 versions.
- Affected:
- up to 3.2
- Fixed in:
- 3.2
- Disclosed:
- Nov 9, 2023
CVE-2023-32739 on NVD →
WP Custom Cursors | WordPress Cursor <= 3.2 - Authenticated (Admin+) Stored Cross-Site Scripting
medium
The WP Custom Cursors | WordPress Cursor Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 3.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissi...
- CVSS:
- 4.4
- Affected:
- up to 3.2
- Fix:
- No patched version reported
- Disclosed:
- Oct 7, 2023
CVE-2023-5911 on NVD →
WP Custom Cursors | WordPress Cursor Plugin [wp-custom-cursors] < 3.2
unknown
[en] The WP Custom Cursors WordPress plugin before 3.2 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by users with a role as low as Admin.
- Affected:
- up to 3.2
- Fixed in:
- 3.2
- Disclosed:
- Jun 19, 2023
CVE-2023-2221 on NVD →
WP Custom Cursors <= 3.1 - Authenticated (Admin+) SQL Injection
critical
The WP Custom Cursors | WordPress Cursor Plugin plugin for WordPress is vulnerable to SQL Injection via the 'edit_row' parameter in all versions up to, and including, 3.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for...
- CVSS:
- 9.1
- Affected:
- up to 3.1
- Fixed in:
- 3.2
- Disclosed:
- May 24, 2023
CVE-2023-2221 on NVD →
WP Custom Cursors < 3.2 - Cross-Site Request Forgery
medium
The WP Custom Cursors plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to 3.2. This is due to missing or incorrect nonce validation on an unknown function. This makes it possible for unauthenticated attackers to call the function via a forged request granted they can trick a site administ...
- CVSS:
- 4.3
- Affected:
- up to 3.2
- Fixed in:
- 3.2
- Disclosed:
- May 15, 2023
CVE-2023-32739 on NVD →
WP Custom Cursors | WordPress Cursor Plugin [wp-custom-cursors] < 3.0.1
unknown
[en] The WP Custom Cursors WordPress plugin before 3.0.1 does not have CSRF check in place when deleting cursors, which could allow attackers to made a logged in admin delete arbitrary cursors via a CSRF attack.
- Affected:
- up to 3.0.1
- Fixed in:
- 3.0.1
- Disclosed:
- Oct 17, 2022
CVE-2022-3151 on NVD →
WP Custom Cursors | WordPress Cursor Plugin [wp-custom-cursors] < 3.0.1
unknown
[en] The WP Custom Cursors WordPress plugin before 3.0.1 does not have CSRF check in place when creating and editing cursors, which could allow attackers to made a logged in admin perform such actions via CSRF attacks. Furthermore, due to the lack of sanitisation and escaping in some of the cursor options, it could als...
- Affected:
- up to 3.0.1
- Fixed in:
- 3.0.1
- Disclosed:
- Oct 17, 2022
CVE-2022-3149 on NVD →
WP Custom Cursors | WordPress Cursor Plugin [wp-custom-cursors] < 3.2
unknown
[en] The WP Custom Cursors WordPress plugin before 3.2 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by high privileged users such as admin
- Affected:
- up to 3.2
- Fixed in:
- 3.2
- Disclosed:
- Oct 17, 2022
CVE-2022-3150 on NVD →
WP Custom Cursors <= 3.0 - Cross-Site Request Forgery to Cursor Manipulation
high
The WP Custom Cursors plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.0. This is due to missing or incorrect nonce validation in the ~/wp-custom-cursors-add-new.php file. This makes it possible for unauthenticated attackers to manipulate cursors, via forged request g...
- CVSS:
- 8.8
- Affected:
- up to 3.0
- Fixed in:
- 3.0.1
- Disclosed:
- Sep 21, 2022
CVE-2022-3151 on NVD →
WP Custom Cursors <= 3.0.1 - Authenticated (Administrator+) SQL Injection
high
The WP Custom Cursors plugin for WordPress is vulnerable to SQL Injection via the ‘edit_row’ parameter and potentially others in versions up to, and including, 3.0.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authe...
- CVSS:
- 7.2
- Affected:
- up to 3.0.2
- Fixed in:
- 3.0.3
- Disclosed:
- Sep 21, 2022
CVE-2022-3150 on NVD →
WP Custom Cursors <= 3.0 - Authenticated (Administrator+) Stored Cross-Site Scripting
medium
The WP Custom Cursors plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘cursor_text’ parameter as well as others in versions up to, and including, 3.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permis...
- CVSS:
- 5.5
- Affected:
- up to 3.0
- Fixed in:
- 3.0.1
- Disclosed:
- Sep 21, 2022
CVE-2022-3149 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database