theme

Attorney Vulnerabilities

6 known security issues reported for the Attorney WordPress theme. Most recent disclosed Jun 19, 2024.

2 medium

Running Attorney on your site? Check whether your installed version is affected.

Scan your site free

Attorney [attorney] <= 3 (unfixed)

unknown

[en] Missing Authorization vulnerability in Hennessey Digital Attorney.This issue affects Attorney: from n/a through 3.

Affected:
up to 3
Fix:
No patched version reported
Disclosed:
Jun 19, 2024

CVE-2022-45832 on NVD →

Attorney [attorney] <= 3 (unfixed)

unknown

[en] Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Hennessey Digital Attorney theme <= 3 theme.

Affected:
up to 3
Fix:
No patched version reported
Disclosed:
Oct 2, 2023

CVE-2023-41692 on NVD →

Attorney <= 3 - Reflected Cross-Site Scripting

medium

The Attorney theme for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a use...

CVSS:
6.1
Affected:
up to 3
Fix:
No patched version reported
Disclosed:
Sep 4, 2023

CVE-2023-41692 on NVD →

Attorney <= 3 - Missing Authorization to Unauthenticated Arbitrary Content Deletion

medium

The Attorney theme for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the hd_delete_index_page function hooked via admin_init in versions up to, and including, 3. This makes it possible for unauthenticated attackers to delete arbitrary posts and content via the 'drop' paramete...

CVSS:
6.5
Affected:
up to 3
Fix:
No patched version reported
Disclosed:
Dec 1, 2022

CVE-2022-45832 on NVD →

Attorney [attorney] <= 3 (unfixed)

unknown

No patched version is available. Dave Jong discovered and reported this Broken Access Control vulnerability in WordPress Attorney Theme. This vulnerability has not been known to be fixed yet.

Affected:
up to 3
Fix:
No patched version reported

Attorney [attorney] <= 3 (unfixed)

unknown

The plugin does not have authorisation and CSRF when deleting post/page, which could allow unauthenticated attackers to delete arbitrary posts or pages

Affected:
up to 3
Fix:
No patched version reported

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database