plugin

Wp125 Vulnerabilities

2 known security issues reported for the Wp125 WordPress plugin. Most recent disclosed Dec 23, 2021.

2 high

Running Wp125 on your site? Check whether your installed version is affected.

Scan your site free

WP125 <= 1.5.4 - Cross-Site Request Forgery to Arbitrary Ad Deletion

high

The WP125 WordPress plugin before 1.5.5 does not have CSRF checks in various action, for example when deleting an ad, allowing attackers to make a logged in admin delete them via a CSRF attack

CVSS:
8.8
Affected:
up to 1.5.4
Fixed in:
1.5.5
Disclosed:
Dec 23, 2021

CVE-2021-25073 on NVD →

WP125 <= 1.4.9 - Cross-Site Request Forgery

high

Cross-site request forgery (CSRF) vulnerability in the Add/Edit page (adminmenus.php) in the WP125 plugin before 1.5.0 for WordPress allows remote attackers to hijack the authentication of administrators for requests that add or edit an ad via unspecified vectors.

CVSS:
8.8
Affected:
up to 1.4.9
Fixed in:
1.5.0
Disclosed:
Mar 26, 2013

CVE-2013-2700 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database