plugin

Wp Dtree 30 Vulnerabilities

3 known security issues reported for the Wp Dtree 30 WordPress plugin. Most recent disclosed Sep 4, 2023.

3 medium

Running Wp Dtree 30 on your site? Check whether your installed version is affected.

Scan your site free

WP-dTree <= 4.4.5 - Cross-Site Request Forgery

medium

The WP-dTree plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 4.4.5. This is due to missing or incorrect nonce validation on the wpdt_option_page() function. This makes it possible for unauthenticated attackers to modify the plugin's settings via a forged request grante...

CVSS:
4.3
Affected:
up to 4.4.5
Fix:
No patched version reported
Disclosed:
Sep 4, 2023

CVE-2023-41667 on NVD →

WP-dTree <= 4.4.5 - Reflected Cross-Site Scripting

medium

The WP-dTree plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 4.4.5 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses a...

CVSS:
6.1
Affected:
up to 4.4.5
Fix:
No patched version reported
Disclosed:
Sep 1, 2023

CVE-2023-41662 on NVD →

WP-dTree <= 4.4.5 - Authenticated (Administrator+) Stored Cross-Site Scripting via plugin settings

medium

The WP-dTree plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin settings in versions up to, and including, 4.4.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level access and above, to inject arbitrary we...

CVSS:
4.4
Affected:
up to 4.4.5
Fix:
No patched version reported
Disclosed:
Apr 19, 2023

CVE-2022-47423 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database