Attorney [attorney] <= 3 (unfixed)
unknown[en] Missing Authorization vulnerability in Hennessey Digital Attorney.This issue affects Attorney: from n/a through 3.
- Affected:
- up to 3
- Fix:
- No patched version reported
- Disclosed:
- Jun 19, 2024
theme
6 known security issues reported for the Attorney WordPress theme. Most recent disclosed Jun 19, 2024.
Running Attorney on your site? Check whether your installed version is affected.
Scan your site free[en] Missing Authorization vulnerability in Hennessey Digital Attorney.This issue affects Attorney: from n/a through 3.
[en] Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Hennessey Digital Attorney theme <= 3 theme.
The Attorney theme for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a use...
The Attorney theme for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the hd_delete_index_page function hooked via admin_init in versions up to, and including, 3. This makes it possible for unauthenticated attackers to delete arbitrary posts and content via the 'drop' paramete...
No patched version is available. Dave Jong discovered and reported this Broken Access Control vulnerability in WordPress Attorney Theme. This vulnerability has not been known to be fixed yet.
The plugin does not have authorisation and CSRF when deleting post/page, which could allow unauthenticated attackers to delete arbitrary posts or pages
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free