plugin

Wp Security Questions Vulnerabilities

6 known security issues reported for the Wp Security Questions WordPress plugin. Most recent disclosed Jul 1, 2023.

1 medium

Running Wp Security Questions on your site? Check whether your installed version is affected.

Scan your site free

WP Security Question [wp-security-questions] <= 1.0.5 (unfixed)

unknown

[en] The WP Security Question plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.0.5. This is due to missing or incorrect nonce validation on the save() function. This makes it possible for unauthenticated attackers to modify the plugin's settings via a forged request g...

Affected:
up to 1.0.5
Fix:
No patched version reported
Disclosed:
Jul 1, 2023

CVE-2021-4386 on NVD →

WP Security Question [wp-security-questions] <= 1.0.5 (unfixed)

unknown
Affected:
up to 1.0.5
Fix:
No patched version reported
Disclosed:
Jun 7, 2023

CVE-2021-4342 on NVD →

WP Security Question <= 1.0.5 - Cross-Site Request Forgery Bypass

medium

The WP Security Question plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.0.5. This is due to missing or incorrect nonce validation on the save() function. This makes it possible for unauthenticated attackers to modify the plugin's settings via a forged request grante...

CVSS:
4.3
Affected:
up to 1.0.5
Fix:
No patched version reported
Disclosed:
Aug 16, 2021

CVE-2021-4386 on NVD →

WP Security Question [wp-security-questions] <= 1.0.5 (unfixed + closed)

unknown

Cross-Site Request Forgery (CSRF) vulnerability discovered by Jerome Bruandet (NinTechNet) in WordPress WP Security Question plugin (versions <= 1.0.5).

Affected:
up to 1.0.5
Fix:
No patched version reported
Disclosed:
Aug 16, 2021

WP Security Question [wp-security-questions] <= 1.0.5 (unfixed)

unknown

Over 70 plugins and themes were vulnerable to Cross-Site Request Forgery due to improperly implemented nonce protection that could be bypassed.

Affected:
up to 1.0.5
Fix:
No patched version reported

WP Security Question [wp-security-questions] <= 1.0.5 (unfixed + closed)

unknown

Multiple plugins are affected by CSRF issues due to a logic flaw in their CSRF checks, which could allow attackers to make users perform unwanted actions rucy &lt;= 0.4.4 wp-backgrounds-lite &lt;= 2.3 wp-security-questions &lt;= 1.0.5 photo-contest &lt;= 1.0.6 opal-estate &lt;= 1.6.11 rays-grid &lt;= 1.2.2

Affected:
up to 1.0.5
Fix:
No patched version reported

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database