WP Security Question [wp-security-questions] <= 1.0.5 (unfixed)
unknown
[en] The WP Security Question plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.0.5. This is due to missing or incorrect nonce validation on the save() function. This makes it possible for unauthenticated attackers to modify the plugin's settings via a forged request g...
- Affected:
- up to 1.0.5
- Fix:
- No patched version reported
- Disclosed:
- Jul 1, 2023
CVE-2021-4386 on NVD →
WP Security Question [wp-security-questions] <= 1.0.5 (unfixed)
unknown
- Affected:
- up to 1.0.5
- Fix:
- No patched version reported
- Disclosed:
- Jun 7, 2023
CVE-2021-4342 on NVD →
WP Security Question <= 1.0.5 - Cross-Site Request Forgery Bypass
medium
The WP Security Question plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.0.5. This is due to missing or incorrect nonce validation on the save() function. This makes it possible for unauthenticated attackers to modify the plugin's settings via a forged request grante...
- CVSS:
- 4.3
- Affected:
- up to 1.0.5
- Fix:
- No patched version reported
- Disclosed:
- Aug 16, 2021
CVE-2021-4386 on NVD →
WP Security Question [wp-security-questions] <= 1.0.5 (unfixed + closed)
unknown
Cross-Site Request Forgery (CSRF) vulnerability discovered by Jerome Bruandet (NinTechNet) in WordPress WP Security Question plugin (versions <= 1.0.5).
- Affected:
- up to 1.0.5
- Fix:
- No patched version reported
- Disclosed:
- Aug 16, 2021
WP Security Question [wp-security-questions] <= 1.0.5 (unfixed)
unknown
Over 70 plugins and themes were vulnerable to Cross-Site Request Forgery due to improperly implemented nonce protection that could be bypassed.
- Affected:
- up to 1.0.5
- Fix:
- No patched version reported
WP Security Question [wp-security-questions] <= 1.0.5 (unfixed + closed)
unknown
Multiple plugins are affected by CSRF issues due to a logic flaw in their CSRF checks, which could allow attackers to make users perform unwanted actions
rucy <= 0.4.4
wp-backgrounds-lite <= 2.3
wp-security-questions <= 1.0.5
photo-contest <= 1.0.6
opal-estate <= 1.6.11
rays-grid <= 1.2.2
- Affected:
- up to 1.0.5
- Fix:
- No patched version reported
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database