plugin

Wp Vipergb Vulnerabilities

6 known security issues reported for the Wp Vipergb WordPress plugin. Most recent disclosed May 24, 2024.

3 medium

Running Wp Vipergb on your site? Check whether your installed version is affected.

Scan your site free

WP-ViperGB [wp-vipergb] < 1.6.2

unknown

[en] The WP-ViperGB plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.6.1. This is due to missing or incorrect nonce validation when saving plugin settings. This makes it possible for unauthenticated attackers to change the plugin's settings via a forged request gr...

Affected:
up to 1.6.2
Fixed in:
1.6.2
Disclosed:
May 24, 2024

CVE-2024-4409 on NVD →

WP-ViperGB <= 1.6.1 - Cross-Site Request Forgery

medium

The WP-ViperGB plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.6.1. This is due to missing or incorrect nonce validation when saving plugin settings. This makes it possible for unauthenticated attackers to change the plugin's settings via a forged request granted...

CVSS:
4.3
Affected:
up to 1.6.1
Fixed in:
1.6.2
Disclosed:
May 23, 2024

CVE-2024-4409 on NVD →

WP-ViperGB [wp-vipergb] < 1.3.16

unknown

[en] The wp-vipergb plugin before 1.3.16 for WordPress has XSS via add_query_arg() and remove_query_arg(), a different issue than CVE-2014-9460.

Affected:
up to 1.3.16
Fixed in:
1.3.16
Disclosed:
Aug 28, 2019

CVE-2015-9356 on NVD →

Viper GuestBook <= 1.3.15 - Cross-Site Scripting

medium

The Viper GuestBook plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including, 1.3.15 due to insufficient input sanitization and output escaping on a query arg. This makes it possible for attackers to inject arbitrary web scripts that execute in a victim's browser.

CVSS:
6.1
Affected:
up to 1.3.16
Fixed in:
1.3.16
Disclosed:
Apr 20, 2015

CVE-2015-9356 on NVD →

WP-ViperGB [wp-vipergb] < 1.3.11

unknown

[en] Multiple cross-site request forgery (CSRF) vulnerabilities in the WP-ViperGB plugin before 1.3.11 for WordPress allow remote attackers to hijack the authentication of administrators for requests that (1) change plugin settings via unspecified vectors or conduct cross-site scripting (XSS) attacks via the (2) vgb_pa...

Affected:
up to 1.3.11
Fixed in:
1.3.11
Disclosed:
Jan 2, 2015

CVE-2014-9460 on NVD →

WP-ViperGB <= 1.3.10 - Cross-Site Request Forgery to Cross-Site Scripting

medium

Multiple cross-site request forgery (CSRF) vulnerabilities in the WP-ViperGB plugin before 1.3.11 for WordPress allow remote attackers to hijack the authentication of administrators for requests that (1) change plugin settings via unspecified vectors or conduct cross-site scripting (XSS) attacks via the (2) vgb_page or...

CVSS:
6.1
Affected:
up to 1.3.10
Fixed in:
1.3.11
Disclosed:
Dec 12, 2014

CVE-2014-9460 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database