plugin

Wp Logs Book Vulnerabilities

7 known security issues reported for the Wp Logs Book WordPress plugin. Most recent disclosed Jun 21, 2024.

1 high 2 medium

Running Wp Logs Book on your site? Check whether your installed version is affected.

Scan your site free

WP Logs Book [wp-logs-book] <= 1.0.1 (unfixed + closed)

unknown

[en] The WP Logs Book WordPress plugin through 1.0.1 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack

Affected:
up to 1.0.1
Fix:
No patched version reported
Disclosed:
Jun 21, 2024

CVE-2024-4474 on NVD →

WP Logs Book [wp-logs-book] <= 1.0.1 (unfixed + closed)

unknown

[en] The WP Logs Book WordPress plugin through 1.0.1 does not have CSRF check when clearing logs, which could allow attackers to make a logged in admin clear the logs them via a CSRF attack

Affected:
up to 1.0.1
Fix:
No patched version reported
Disclosed:
Jun 21, 2024

CVE-2024-4475 on NVD →

WP Logs Book [wp-logs-book] <= 1.0.1 (unfixed + closed)

unknown

[en] The WP Logs Book WordPress plugin through 1.0.1 does not sanitise and escape some of its log data before outputting them back in an admin dashboard, leading to an Unauthenticated Stored Cross-Site Scripting

Affected:
up to 1.0.1
Fix:
No patched version reported
Disclosed:
Jun 21, 2024

CVE-2024-4477 on NVD →

WP Logs Book <= 1.0.1 - Unauthenticated Stored Cross-Site Scripting

high

The WP Logs Book plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 1.0.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user acces...

CVSS:
7.2
Affected:
up to 1.0.1
Fix:
No patched version reported
Disclosed:
May 31, 2024

CVE-2024-4477 on NVD →

WP Logs Book <= 1.0.1 - Cross-Site Request Forgery to Log Disabling

medium

The WP Logs Book plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.1. This is due to missing or incorrect nonce validation on a function. This makes it possible for unauthenticated attackers to disable logging via a forged request granted they can trick a site ad...

CVSS:
4.3
Affected:
up to 1.0.1
Fix:
No patched version reported
Disclosed:
May 31, 2024

CVE-2024-4474 on NVD →

WP Logs Book <= 1.0.1 - Cross-Site Request Forgery to Log Clearing

medium

The WP Logs Book plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.1. This is due to missing or incorrect nonce validation on a function. This makes it possible for unauthenticated attackers to clear logs via a forged request granted they can trick a site adminis...

CVSS:
4.3
Affected:
up to 1.0.1
Fix:
No patched version reported
Disclosed:
May 31, 2024

CVE-2024-4475 on NVD →

WP Logs Book [wp-logs-book] <= 1.0.1 (unfixed + closed)

unknown
Affected:
up to 1.0.1
Fix:
No patched version reported

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database