Total
11 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2023-5411 | 1 Funnelforms | 1 Funnelforms | 2024-02-28 | N/A | 4.3 MEDIUM |
The Funnelforms Free plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the fnsf_af2_save_post function in versions up to, and including, 3.4. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to modify certain post values. Note that the extent of modification is limited due to fixed values passed to the wp_update_post function. | |||||
CVE-2023-5417 | 1 Funnelforms | 1 Funnelforms | 2024-02-28 | N/A | 4.3 MEDIUM |
The Funnelforms Free plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the fnsf_update_category function in versions up to, and including, 3.4. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to modify the Funnelforms category for a given post ID. | |||||
CVE-2023-5382 | 1 Funnelforms | 1 Funnelforms | 2024-02-28 | N/A | 4.3 MEDIUM |
The Funnelforms Free plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.4. This is due to missing or incorrect nonce validation on the fnsf_delete_posts function. This makes it possible for unauthenticated attackers to delete arbitrary posts via a forged request granted they can trick a site administrator into performing an action such as clicking on a link. | |||||
CVE-2023-5383 | 1 Funnelforms | 1 Funnelforms | 2024-02-28 | N/A | 4.3 MEDIUM |
The Funnelforms Free plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.4. This is due to missing or incorrect nonce validation on the fnsf_copy_posts function. This makes it possible for unauthenticated attackers to create copies of arbitrary posts via a forged request granted they can trick a site administrator into performing an action such as clicking on a link. | |||||
CVE-2023-5385 | 1 Funnelforms | 1 Funnelforms | 2024-02-28 | N/A | 4.3 MEDIUM |
The Funnelforms Free plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the fnsf_copy_posts function in versions up to, and including, 3.4. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to create copies of arbitrary posts. | |||||
CVE-2023-5419 | 1 Funnelforms | 1 Funnelforms | 2024-02-28 | N/A | 4.3 MEDIUM |
The Funnelforms Free plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the fnsf_af2_test_mail function in versions up to, and including, 3.4. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to send test emails to an arbitrary email address. | |||||
CVE-2023-5387 | 1 Funnelforms | 1 Funnelforms | 2024-02-28 | N/A | 4.3 MEDIUM |
The Funnelforms Free plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the fnsf_af2_trigger_dark_mode function in versions up to, and including, 3.4. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to enable or disable the dark mode plugin setting. | |||||
CVE-2023-5416 | 1 Funnelforms | 1 Funnelforms | 2024-02-28 | N/A | 4.3 MEDIUM |
The Funnelforms Free plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the fnsf_delete_category function in versions up to, and including, 3.4. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to delete categories. | |||||
CVE-2023-5386 | 1 Funnelforms | 1 Funnelforms | 2024-02-28 | N/A | 4.3 MEDIUM |
The Funnelforms Free plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the fnsf_delete_posts function in versions up to, and including, 3.4. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to delete arbitrary posts, including administrator posts, and posts not related to the Funnelforms Free plugin. | |||||
CVE-2023-5415 | 1 Funnelforms | 1 Funnelforms | 2024-02-28 | N/A | 4.3 MEDIUM |
The Funnelforms Free plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the fnsf_add_category function in versions up to, and including, 3.4. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to add new categories. | |||||
CVE-2023-4950 | 1 Funnelforms | 1 Funnelforms | 2024-02-28 | N/A | 6.1 MEDIUM |
The Interactive Contact Form and Multi Step Form Builder WordPress plugin before 3.4 does not sanitise and escape some parameters, which could allow unauthenticated users to perform Cross-Site Scripting attacks |