plugin

Wp Publications Vulnerabilities

4 known security issues reported for the Wp Publications WordPress plugin. Most recent disclosed Dec 27, 2024.

1 high 1 medium

Running Wp Publications on your site? Check whether your installed version is affected.

Scan your site free

wp-publications [wp-publications] <= 1.2 (unfixed + closed)

unknown

[en] The wp-publications WordPress plugin through 1.2 does not escape filenames before outputting them back in the page, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

Affected:
up to 1.2
Fix:
No patched version reported
Disclosed:
Dec 27, 2024

CVE-2024-11605 on NVD →

WP Publications <= 1.2 - Authenticated (Admin+) Stored Cross-Site Scripting

medium

The wp-publications plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 1.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arb...

CVSS:
4.4
Affected:
up to 1.2
Fix:
No patched version reported
Disclosed:
Dec 6, 2024

CVE-2024-11605 on NVD →

wp-publications [wp-publications] < 1.1 (closed)

unknown

[en] The wp-publications WordPress plugin is vulnerable to restrictive local file inclusion via the Q_FILE parameter found in the ~/bibtexbrowser.php file which allows attackers to include local zip files and achieve remote code execution, in versions up to and including 0.0.

Affected:
up to 1.1
Fixed in:
1.1
Disclosed:
Sep 10, 2021

CVE-2021-38360 on NVD →

wp-publications < 1.1 - Local File Inclusion

high

The wp-publications WordPress plugin is vulnerable to restrictive local file inclusion via the Q_FILE parameter found in the ~/bibtexbrowser.php file which allows attackers to include local zip files and achieve remote code execution, in versions up to and including 0.0.

CVSS:
8.3
Affected:
up to 0.0
Fixed in:
1.1
Disclosed:
Sep 9, 2021

CVE-2021-38360 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database