Ask Me < 6.8.7 - Cross-Site Request Forgery
high
The Ask Me theme for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, but not including, 6.8.7. This is due to missing or incorrect nonce validation on one of its functions. This makes it possible for unauthenticated attackers to invoke that function, via forged request granted they can trick a...
- CVSS:
- 8.8
- Affected:
- up to 6.8.7
- Fixed in:
- 6.8.7
- Disclosed:
- Oct 28, 2022
CVE-2022-3750 on NVD →
Ask Me <= 6.8.3 - Cross-Site Request Forgery
high
The Ask Me theme for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 6.8.3. This is due to missing or incorrect nonce validation when editing profiles. This makes it possible for unauthenticated attackers to edit user profiles, via forged request granted they can trick a site adm...
- CVSS:
- 8.8
- Affected:
- up to 6.8.3
- Fixed in:
- 6.8.4
- Disclosed:
- Aug 1, 2022
CVE-2022-1251 on NVD →
Ask Me <= 6.8.1 - Cross-Site Request Forgery
high
The Ask me WordPress theme before 6.8.2 does not perform CSRF checks for any of its AJAX actions, allowing an attacker to trick logged in users to perform various actions on their behalf on the site.
- CVSS:
- 8.8
- Affected:
- up to 6.8.2
- Fixed in:
- 6.8.2
- Disclosed:
- May 16, 2022
CVE-2022-1424 on NVD →
Ask Me <= 6.8.1 - Reflected Cross-Site Scripting
medium
The Ask me WordPress theme before 6.8.2 does not properly sanitise and escape several of the fields in the Edit Profile page, leading to Reflected Cross-Site Scripting issues
- CVSS:
- 6.1
- Affected:
- up to 6.8.2
- Fixed in:
- 6.8.2
- Disclosed:
- May 16, 2022
CVE-2022-1241 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database