Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
wordpress wordpress 3.4.2 vulnerabilities and exploits
(subscribe to this query)
NA
CVE-2024-2845
The BetterDocs – Best Documentation, FAQ & Knowledge Base Plugin with AI Support & Instant Answer For Elementor & Gutenberg plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in all versions up to, and including,...
NA
CVE-2024-1321
The EventPrime – Events Calendar, Bookings and Tickets plugin for WordPress is vulnerable to payment bypass in all versions up to, and including, 3.4.2. This is due to the plugin allowing unauthenticated users to update the status of order payments. This makes it possible f...
NA
CVE-2024-1123
The EventPrime – Events Calendar, Bookings and Tickets plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the save_frontend_event_submission() function in all versions up to, and including, 3.4.2. This makes it possi...
6.5
CVSSv3
CVE-2023-5990
The Interactive Contact Form and Multi Step Form Builder with Drag & Drop Editor WordPress plugin prior to 3.4.2 does not have CSRF checks on some of its form actions such as deletion and duplication, which could allow malicious users to make logged in admin perform such acti...
Funnelforms Funnelforms Free
4.3
CVSSv3
CVE-2020-36758
The RSS Aggregator by Feedzy plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.4.2. This is due to missing or incorrect nonce validation on the save_feedzy_post_type_meta() function. This makes it possible for unauthenticated mal...
Themeisle Rss Aggregator By Feedzy
9.8
CVSSv3
CVE-2023-1478
The Hummingbird WordPress plugin prior to 3.4.2 does not validate the generated file path for page cache files before writing them, leading to a path traversal vulnerability in the page cache module.
Incsub Hummingbird
6.5
CVSSv3
CVE-2022-3926
The WP OAuth Server (OAuth Authentication) WordPress plugin prior to 3.4.2 does not have CSRF check when regenerating secrets, which could allow malicious users to make logged in admins regenerate the secret of an arbitrary client given they know the client ID
Wp-oauth Wp Oauth Server
5.4
CVSSv3
CVE-2021-24738
The Logo Carousel WordPress plugin prior to 3.4.2 does not validate and escape the "Logo Margin" carousel option, which could allow users with a role as low as Contributor to perform Stored Cross-Site Scripting attacks
Shapedplugin Logo Carousel
8.1
CVSSv3
CVE-2021-24739
The Logo Carousel WordPress plugin prior to 3.4.2 allows users with a role as low as Contributor to duplicate and view arbitrary private posts made by other users via the Carousel Duplication feature
Shapedplugin Logo Carousel
7.5
CVSSv3
CVE-2021-24651
The Poll Maker WordPress plugin prior to 3.4.2 allows unauthenticated users to perform SQL injection via the ays_finish_poll AJAX action. While the result is not disclosed in the response, it is possible to use a timing attack to exfiltrate data such as password hash.
Ays-pro Poll Maker
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2023-30310
CVE-2024-21683
CVE-2024-22187
chrome
deserialization
XPath injection
CVE-2024-27842
denial of service
CVE-2024-24851
google
CVE-2024-35400
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
1
2
3
4
NEXT »