plugin

Wp Custom Cursors Vulnerabilities

12 known security issues reported for the Wp Custom Cursors WordPress plugin. Most recent disclosed Jan 8, 2024.

1 critical 2 high 3 medium

Running Wp Custom Cursors on your site? Check whether your installed version is affected.

Scan your site free

WP Custom Cursors | WordPress Cursor Plugin [wp-custom-cursors] <= 3.3 (unfixed)

unknown

[en] The WP Custom Cursors | WordPress Cursor Plugin WordPress plugin through 3.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

Affected:
up to 3.3
Fix:
No patched version reported
Disclosed:
Jan 8, 2024

CVE-2023-5911 on NVD →

WP Custom Cursors | WordPress Cursor Plugin [wp-custom-cursors] < 3.2

unknown

[en] Cross-Site Request Forgery (CSRF) vulnerability in Web_Trendy WP Custom Cursors | WordPress Cursor Plugin plugin < 3.2 versions.

Affected:
up to 3.2
Fixed in:
3.2
Disclosed:
Nov 9, 2023

CVE-2023-32739 on NVD →

WP Custom Cursors | WordPress Cursor <= 3.2 - Authenticated (Admin+) Stored Cross-Site Scripting

medium

The WP Custom Cursors | WordPress Cursor Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 3.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissi...

CVSS:
4.4
Affected:
up to 3.2
Fix:
No patched version reported
Disclosed:
Oct 7, 2023

CVE-2023-5911 on NVD →

WP Custom Cursors | WordPress Cursor Plugin [wp-custom-cursors] < 3.2

unknown

[en] The WP Custom Cursors WordPress plugin before 3.2 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by users with a role as low as Admin.

Affected:
up to 3.2
Fixed in:
3.2
Disclosed:
Jun 19, 2023

CVE-2023-2221 on NVD →

WP Custom Cursors <= 3.1 - Authenticated (Admin+) SQL Injection

critical

The WP Custom Cursors | WordPress Cursor Plugin plugin for WordPress is vulnerable to SQL Injection via the 'edit_row' parameter in all versions up to, and including, 3.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for...

CVSS:
9.1
Affected:
up to 3.1
Fixed in:
3.2
Disclosed:
May 24, 2023

CVE-2023-2221 on NVD →

WP Custom Cursors < 3.2 - Cross-Site Request Forgery

medium

The WP Custom Cursors plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to 3.2. This is due to missing or incorrect nonce validation on an unknown function. This makes it possible for unauthenticated attackers to call the function via a forged request granted they can trick a site administ...

CVSS:
4.3
Affected:
up to 3.2
Fixed in:
3.2
Disclosed:
May 15, 2023

CVE-2023-32739 on NVD →

WP Custom Cursors | WordPress Cursor Plugin [wp-custom-cursors] < 3.0.1

unknown

[en] The WP Custom Cursors WordPress plugin before 3.0.1 does not have CSRF check in place when deleting cursors, which could allow attackers to made a logged in admin delete arbitrary cursors via a CSRF attack.

Affected:
up to 3.0.1
Fixed in:
3.0.1
Disclosed:
Oct 17, 2022

CVE-2022-3151 on NVD →

WP Custom Cursors | WordPress Cursor Plugin [wp-custom-cursors] < 3.0.1

unknown

[en] The WP Custom Cursors WordPress plugin before 3.0.1 does not have CSRF check in place when creating and editing cursors, which could allow attackers to made a logged in admin perform such actions via CSRF attacks. Furthermore, due to the lack of sanitisation and escaping in some of the cursor options, it could als...

Affected:
up to 3.0.1
Fixed in:
3.0.1
Disclosed:
Oct 17, 2022

CVE-2022-3149 on NVD →

WP Custom Cursors | WordPress Cursor Plugin [wp-custom-cursors] < 3.2

unknown

[en] The WP Custom Cursors WordPress plugin before 3.2 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by high privileged users such as admin

Affected:
up to 3.2
Fixed in:
3.2
Disclosed:
Oct 17, 2022

CVE-2022-3150 on NVD →

WP Custom Cursors <= 3.0 - Cross-Site Request Forgery to Cursor Manipulation

high

The WP Custom Cursors plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.0. This is due to missing or incorrect nonce validation in the ~/wp-custom-cursors-add-new.php file. This makes it possible for unauthenticated attackers to manipulate cursors, via forged request g...

CVSS:
8.8
Affected:
up to 3.0
Fixed in:
3.0.1
Disclosed:
Sep 21, 2022

CVE-2022-3151 on NVD →

WP Custom Cursors <= 3.0.1 - Authenticated (Administrator+) SQL Injection

high

The WP Custom Cursors plugin for WordPress is vulnerable to SQL Injection via the ‘edit_row’ parameter and potentially others in versions up to, and including, 3.0.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authe...

CVSS:
7.2
Affected:
up to 3.0.2
Fixed in:
3.0.3
Disclosed:
Sep 21, 2022

CVE-2022-3150 on NVD →

WP Custom Cursors <= 3.0 - Authenticated (Administrator+) Stored Cross-Site Scripting

medium

The WP Custom Cursors plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘cursor_text’ parameter as well as others in versions up to, and including, 3.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permis...

CVSS:
5.5
Affected:
up to 3.0
Fixed in:
3.0.1
Disclosed:
Sep 21, 2022

CVE-2022-3149 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database