plugin

Wpbrutalai Vulnerabilities

6 known security issues reported for the Wpbrutalai WordPress plugin. Most recent disclosed Aug 14, 2023.

1 high 2 medium

Running Wpbrutalai on your site? Check whether your installed version is affected.

Scan your site free

WP Brutal AI [wpbrutalai] < 2.06

unknown

[en] The WP Brutal AI WordPress plugin before 2.06 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

Affected:
up to 2.06
Fixed in:
2.06
Disclosed:
Aug 14, 2023

CVE-2023-2606 on NVD →

WP Brutal AI < 2.06 - Authenticated (Administrator+) Stored Cross-Site Scripting

medium

The WP Brutal AI plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versions up to, but not including, 2.06 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbit...

CVSS:
4.4
Affected:
up to 2.06
Fixed in:
2.06
Disclosed:
Jul 19, 2023

CVE-2023-2606 on NVD →

WP Brutal AI [wpbrutalai] < 2.0.1

unknown

[en] The wpbrutalai WordPress plugin before 2.0.1 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against a logged in high privilege users such as admin.

Affected:
up to 2.0.1
Fixed in:
2.0.1
Disclosed:
Jun 27, 2023

CVE-2023-2605 on NVD →

WP Brutal AI [wpbrutalai] < 2.0.0

unknown

[en] The wpbrutalai WordPress plugin before 2.0.0 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by admin via CSRF.

Affected:
up to 2.0.0
Fixed in:
2.0.0
Disclosed:
Jun 27, 2023

CVE-2023-2601 on NVD →

WP Brutal AI < 2.0.0 - Cross-Site Request Forgery to SQL Injection

high

The WP Brutal AI plugin for WordPress is vulnerable to SQL Injection via an unknown parameter in versions before 2.0.0 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. Additionally it lacks a nonce check on this functionality. This makes it possi...

CVSS:
8.8
Affected:
up to 2.0.0
Fixed in:
2.0.0
Disclosed:
Jun 5, 2023

CVE-2023-2601 on NVD →

WP Brutal AI < 2.0.1 - Reflected Cross-Site Scripting

medium

The WP Brutal AI plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via admin settings in versions before 2.0.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successful...

CVSS:
6.1
Affected:
up to 2.0.1
Fixed in:
2.0.1
Disclosed:
Jun 5, 2023

CVE-2023-2605 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database