plugin

Wp Extra Vulnerabilities

4 known security issues reported for the Wp Extra WordPress plugin. Most recent disclosed Nov 16, 2023.

1 high 3 medium

Running Wp Extra on your site? Check whether your installed version is affected.

Scan your site free

WP EXtra <= 6.4 - Cross-Site Request Forgery ToolImport

medium

The WP EXtra plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 6.4. This is due to missing or incorrect nonce validation on the ToolImport function. This makes it possible for unauthenticated attackers to change plugin settings via a forged request granted they can trick...

CVSS:
4.3
Affected:
up to 6.4
Fixed in:
6.5
Disclosed:
Nov 16, 2023

CVE-2023-47825 on NVD →

WP EXtra <= 6.2 - Missing Authorization to Arbitrary Email Sending

medium

The WP EXtra plugin for WordPress is vulnerable to unauthorized access to restricted functionality due to a missing capability check on the 'test-email' section of the register() function in versions up to, and including, 6.2. This makes it possible for authenticated attackers, with minimal permissions such as a subscr...

CVSS:
4.3
Affected:
up to 6.2
Fixed in:
6.3
Disclosed:
Oct 25, 2023

CVE-2023-5314 on NVD →

WP EXtra <= 6.2 - Missing Authorization to .htaccess File Modification

high

The WP EXtra plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the register() function in versions up to, and including, 6.2. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to modify the contents of the .htacces...

CVSS:
8.8
Affected:
up to 6.2
Fixed in:
6.3
Disclosed:
Oct 24, 2023

CVE-2023-5311 on NVD →

WP EXtra <= 6.2 - Missing Authorization to Export Settings

medium

The WP EXtra plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the register() function in versions up to, and including, 6.2. This makes it possible for authenticated attackers, with subscriber-level access and above, to export plugin settings.

CVSS:
4.3
Affected:
up to 6.2
Fixed in:
6.3
Disclosed:
Oct 19, 2023

CVE-2023-46212 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database