plugin

Wp Multisite Content Copier Vulnerabilities

9 known security issues reported for the Wp Multisite Content Copier WordPress plugin. Most recent disclosed Jul 20, 2024.

3 medium

Running Wp Multisite Content Copier on your site? Check whether your installed version is affected.

Scan your site free

WordPress Multisite Content Copier/Updater [wp-multisite-content-copier] < 2.0.1

unknown

[en] Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Obtain Infotech Multisite Content Copier/Updater allows Reflected XSS.This issue affects Multisite Content Copier/Updater: from n/a through 1.5.0.

Affected:
up to 2.0.1
Fixed in:
2.0.1
Disclosed:
Jul 20, 2024

CVE-2024-38673 on NVD →

Multisite Content Copier/Updater <= 2.0.0 - Reflected Cross-Site Scripting

medium

The Multisite Content Copier/Updater plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 2.0.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they...

CVSS:
6.1
Affected:
up to 2.0.0
Fixed in:
2.0.1
Disclosed:
Jul 10, 2024

CVE-2024-38673 on NVD →

WordPress Multisite Content Copier/Updater <= 1.4.0 - Cross-Site Scripting

medium

The WordPress Multisite Content Copier/Updater plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via several parameters in versions up to, and including, 1.4.0 due to insufficient input sanitization and output escaping. This makes it possible for attackers to inject arbitrary web scripts in pages th...

CVSS:
6.1
Affected:
up to 1.4.0
Fixed in:
1.5.0
Disclosed:
Jun 17, 2022

WordPress Multisite Content Copier/Updater [wp-multisite-content-copier] < 1.5.0

unknown

The WordPress Multisite Content Copier/Updater plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via several parameters in versions up to, and including, 1.4.0 due to insufficient input sanitization and output escaping. This makes it possible for attackers to inject arbitrary web scripts in pages th...

Affected:
up to 1.5.0
Fixed in:
1.5.0
Disclosed:
Jun 17, 2022

WordPress Multisite Content Copier/Updater [wp-multisite-content-copier] < 2.1.2

unknown

[en] The WordPress Multisite Content Copier/Updater WordPress plugin before 2.1.2 does not sanitise and escape the s parameter before outputting it back in an attribute, leading to a Reflected Cross-Site Scripting issue in the network dashboard

Affected:
up to 2.1.2
Fixed in:
2.1.2
Disclosed:
Mar 14, 2022

CVE-2022-0503 on NVD →

WordPress Multisite Content Copier/Updater [wp-multisite-content-copier] < 1.5.0

unknown

[en] The WordPress Multisite Content Copier/Updater WordPress plugin before 2.1.0 does not sanitise and escape the wmcc_content_type, wmcc_source_blog and wmcc_record_per_page parameters before outputting them back in attributes, leading to Reflected Cross-Site Scripting issues

Affected:
up to 1.5.0
Fixed in:
1.5.0
Disclosed:
Mar 7, 2022

CVE-2021-25039 on NVD →

Multisite Content Copier/Updater <= 1.4.0 - Reflected Cross-Site Scripting

medium

The WordPress Multisite Content Copier/Updater WordPress plugin before 1.5.0 does not sanitise and escape the wmcc_content_type, wmcc_source_blog and wmcc_record_per_page parameters before outputting them back in attributes, leading to Reflected Cross-Site Scripting issues

CVSS:
6.1
Affected:
up to 1.4.0
Fixed in:
1.5.0
Disclosed:
Feb 7, 2022

CVE-2021-25039 on NVD →

WordPress Multisite Content Copier/Updater [wp-multisite-content-copier] < 1.5.0

unknown

SQL Injection (SQLi) vulnerability discovered in WordPress WordPress Multisite Content Copier/Updater plugin (versions <= 1.4.0).

Affected:
up to 1.5.0
Fixed in:
1.5.0
Disclosed:
Jan 6, 2022

WordPress Multisite Content Copier/Updater [wp-multisite-content-copier] < 1.5.0

unknown

Reflected Cross-Site Scripting (XSS) vulnerability discovered in WordPress Multisite Content Copier/Updater plugin (versions <= 1.4.0).

Affected:
up to 1.5.0
Fixed in:
1.5.0
Disclosed:
Jan 6, 2022

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database