theme

Ask Me Vulnerabilities

4 known security issues reported for the Ask Me WordPress theme. Most recent disclosed Oct 28, 2022.

3 high 1 medium

Running Ask Me on your site? Check whether your installed version is affected.

Scan your site free

Ask Me < 6.8.7 - Cross-Site Request Forgery

high

The Ask Me theme for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, but not including, 6.8.7. This is due to missing or incorrect nonce validation on one of its functions. This makes it possible for unauthenticated attackers to invoke that function, via forged request granted they can trick a...

CVSS:
8.8
Affected:
up to 6.8.7
Fixed in:
6.8.7
Disclosed:
Oct 28, 2022

CVE-2022-3750 on NVD →

Ask Me <= 6.8.3 - Cross-Site Request Forgery

high

The Ask Me theme for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 6.8.3. This is due to missing or incorrect nonce validation when editing profiles. This makes it possible for unauthenticated attackers to edit user profiles, via forged request granted they can trick a site adm...

CVSS:
8.8
Affected:
up to 6.8.3
Fixed in:
6.8.4
Disclosed:
Aug 1, 2022

CVE-2022-1251 on NVD →

Ask Me <= 6.8.1 - Cross-Site Request Forgery

high

The Ask me WordPress theme before 6.8.2 does not perform CSRF checks for any of its AJAX actions, allowing an attacker to trick logged in users to perform various actions on their behalf on the site.

CVSS:
8.8
Affected:
up to 6.8.2
Fixed in:
6.8.2
Disclosed:
May 16, 2022

CVE-2022-1424 on NVD →

Ask Me <= 6.8.1 - Reflected Cross-Site Scripting

medium

The Ask me WordPress theme before 6.8.2 does not properly sanitise and escape several of the fields in the Edit Profile page, leading to Reflected Cross-Site Scripting issues

CVSS:
6.1
Affected:
up to 6.8.2
Fixed in:
6.8.2
Disclosed:
May 16, 2022

CVE-2022-1241 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database