WP EXtra <= 6.4 - Cross-Site Request Forgery ToolImport
medium
The WP EXtra plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 6.4. This is due to missing or incorrect nonce validation on the ToolImport function. This makes it possible for unauthenticated attackers to change plugin settings via a forged request granted they can trick...
- CVSS:
- 4.3
- Affected:
- up to 6.4
- Fixed in:
- 6.5
- Disclosed:
- Nov 16, 2023
CVE-2023-47825 on NVD →
WP EXtra <= 6.2 - Missing Authorization to Arbitrary Email Sending
medium
The WP EXtra plugin for WordPress is vulnerable to unauthorized access to restricted functionality due to a missing capability check on the 'test-email' section of the register() function in versions up to, and including, 6.2. This makes it possible for authenticated attackers, with minimal permissions such as a subscr...
- CVSS:
- 4.3
- Affected:
- up to 6.2
- Fixed in:
- 6.3
- Disclosed:
- Oct 25, 2023
CVE-2023-5314 on NVD →
WP EXtra <= 6.2 - Missing Authorization to .htaccess File Modification
high
The WP EXtra plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the register() function in versions up to, and including, 6.2. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to modify the contents of the .htacces...
- CVSS:
- 8.8
- Affected:
- up to 6.2
- Fixed in:
- 6.3
- Disclosed:
- Oct 24, 2023
CVE-2023-5311 on NVD →
WP EXtra <= 6.2 - Missing Authorization to Export Settings
medium
The WP EXtra plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the register() function in versions up to, and including, 6.2. This makes it possible for authenticated attackers, with subscriber-level access and above, to export plugin settings.
- CVSS:
- 4.3
- Affected:
- up to 6.2
- Fixed in:
- 6.3
- Disclosed:
- Oct 19, 2023
CVE-2023-46212 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database