WP Prayer <= 2.0.9 - Cross-Site Request Forgery to Arbitrary Prayer Deletion
medium
The WP Prayer plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.0.9. This is due to missing or incorrect nonce validation on the wpe_manage_prayer page. This makes it possible for unauthenticated attackers to delete prayers via a forged request granted they can tri...
- CVSS:
- 4.3
- Affected:
- up to 2.0.9
- Fix:
- No patched version reported
- Disclosed:
- Apr 24, 2024
CVE-2024-3407 on NVD →
WP Prayer <= 2.0.9 - Cross-Site Request Forgery to Email Settings Update
medium
The WP Prayer plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.0.9. This is due to missing or incorrect nonce validation on the wpe_manage_email_settings page. This makes it possible for unauthenticated attackers to update email settings via a forged request grant...
- CVSS:
- 4.3
- Affected:
- up to 2.0.9
- Fix:
- No patched version reported
- Disclosed:
- Apr 24, 2024
CVE-2024-3406 on NVD →
WP Prayer <= 2.0.9 - Cross-Site Request Forgery to Settings Update
medium
The WP Prayer plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.0.9. This is due to missing or incorrect nonce validation on the wpe_manage_settings page. This makes it possible for unauthenticated attackers to update plugin settings via a forged request granted th...
- CVSS:
- 4.3
- Affected:
- up to 2.0.9
- Fix:
- No patched version reported
- Disclosed:
- Apr 24, 2024
CVE-2024-3405 on NVD →
WP Prayer <= 1.9.6 - Authenticated(Admin+) Stored Cross-Site Scripting
medium
The WP Prayer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versions up to, and including, 1.9.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrative-level permissions and above, to inject arbitrary...
- CVSS:
- 5.5
- Affected:
- up to 1.9.6
- Fixed in:
- 1.9.7
- Disclosed:
- Feb 14, 2023
CVE-2023-25705 on NVD →
WP Prayer <= 1.5.4 - Cross-Site Request Forgery
medium
The WP Prayer plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.5.4. This is due to missing or incorrect nonce validation on the wpe_ajax_call function. This makes it possible for unauthenticated attackers to have users unknowingly execute actions via a forged request.
- CVSS:
- 4.3
- Affected:
- up to 1.5.5
- Fixed in:
- 1.5.5
- Disclosed:
- Jun 30, 2021
WP Prayer <= 1.6.5 - Cross-Site Request Forgery Bypass
medium
The WP Prayer plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.6.5. This is due to missing or incorrect nonce validation on the save() and export() functions. This makes it possible for unauthenticated attackers to save plugin settings and trigger a data export via a...
- CVSS:
- 4.3
- Affected:
- up to 1.6.5
- Fixed in:
- 1.6.6
- Disclosed:
- Jun 8, 2021
CVE-2021-4412 on NVD →
WP Prayer <= 1.6.1 - Authenticated Stored Cross-Site Scripting
medium
The WP Prayer WordPress plugin before 1.6.2 provides the functionality to store requested prayers/praises and list them on a WordPress website. These stored prayer/praise requests can be listed by using the WP Prayer engine. An authenticated WordPress user with any role can fill in the form to request a prayer. The for...
- CVSS:
- 6.4
- Affected:
- up to 1.6.2
- Fixed in:
- 1.6.2
- Disclosed:
- May 17, 2021
CVE-2021-24313 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database