Common Vulnerabilities

In the Lana Codes Common Vulnerability Database (LANACOMMONVDB), we collect the vulnerabilities we discover in other systems and provide standard descriptions.

CVE ID:

CVE-2023-26523

WordPress Plugin

calculated-fields-form <= 1.1.120

Vulnerability Type:

Cross-Site Request Forgery (CSRF)

Date:

2022-10-14

The plugin does not have Cross-Site Request Forgery (CSRF) check when submitting feedback, which could allow attackers to make logged in users do such action on their behalf via a Cross-Site Request Forgery (CSRF) attack.

CVE ID:

CVE-2023-25039

WordPress Plugin

codepeople-post-map <= 1.0.43

Vulnerability Type:

Cross-Site Request Forgery (CSRF)

Date:

2022-10-14

The plugin does not have Cross-Site Request Forgery (CSRF) check when submitting feedback, which could allow attackers to make logged in users do such action on their behalf via a Cross-Site Request Forgery (CSRF) attack.

CVE ID:

CVE-2023-26521

WordPress Plugin

search-in-place <= 1.0.104

Vulnerability Type:

Cross-Site Request Forgery (CSRF)

Date:

2022-10-14

The plugin does not have Cross-Site Request Forgery (CSRF) check when submitting feedback, which could allow attackers to make logged in users do such action on their behalf via a Cross-Site Request Forgery (CSRF) attack.

CVE ID:

CVE-2022-3631

WordPress Plugin

dpt-oauth-client <= 1.1.0

Vulnerability Type:

Cross-Site Scripting (XSS)

Date:

2022-10-10

The plugin does not sanitize and escape some of its settings, which could allow high-privilege users such as admin to perform Stored Cross-Site Scripting (XSS) attacks even when the unfiltered_html capability is disallowed (for example, in multisite setup).

CVE ID:

CVE-2022-3632

WordPress Plugin

dpt-oauth-client <= 1.1.0

Vulnerability Type:

Cross-Site Request Forgery (CSRF)

Date:

2022-10-10

The plugin does not have Cross-Site Request Forgery (CSRF) check in some places, which could allow attackers to make logged-in users perform unwanted actions.

CVE ID:

CVE-2023-25065

WordPress Plugin

wp-expand-tabs-free <= 2.1.14

Vulnerability Type:

Cross-Site Request Forgery (CSRF)

Date:

2022-10-03

The plugin does not have proper Cross-Site Request Forgery (CSRF) check in some places, for example when importing shortcodes, which could allow attackers to make logged in admins perform unwanted actions via Cross-Site Request Forgery (CSRF) attacks.

CVE ID:

CVE-2022-45073

WordPress Plugin

wp-rest-api-authentication <= 2.4.0

Vulnerability Type:

Cross-Site Request Forgery (CSRF)

Date:

2022-09-13

The plugin does not have Cross-Site Request Forgery (CSRF) check in place when updating its settings, which could allow attackers to make a logged in admin change them via a Cross-Site Request Forgery (CSRF) attack.

CVE ID:

CVE-2022-41695

WordPress Plugin

traffic-manager <= 1.4.5

Vulnerability Type:

Cross-Site Request Forgery (CSRF)

Date:

2022-09-13

The plugin does not have proper Cross-Site Request Forgery (CSRF) check in some places, which could allow attackers to make logged in admins perform unwanted actions via Cross-Site Request Forgery (CSRF) attacks.

CVE ID:

CVE-2022-42460

WordPress Plugin

traffic-manager <= 1.4.5

Vulnerability Type:

Cross-Site Scripting (XSS),
Missing Authorization

Date:

2022-09-13

The plugin does not authorisation and does not sanitize as well as escape some parameters, which could allow users with a role as low as subscriber to perform Stored Cross-Site Scripting (XSS) attacks.

CVE ID:

CVE-2022-38468

WordPress Plugin

nextgen-gallery <= 3.28

Vulnerability Type:

Cross-Site Request Forgery (CSRF)

Date:

2022-09-13

The plugin does not have Cross-Site Request Forgery (CSRF) check when modify the thumbnail, which could allow attackers to make logged in users with the edit_post capability to perform such action via a Cross-Site Request Forgery (CSRF) attack.

CVE ID:

CVE-2022-40692

WordPress Plugin

sunshine-photo-cart <= 2.9.13

Vulnerability Type:

Cross-Site Request Forgery (CSRF)

Date:

2022-09-09

The plugin does not have Cross-Site Request Forgery (CSRF) check when updating an image location, which could allow attackers to make logged in users perform such action via a Cross-Site Request Forgery (CSRF) attack.

CVE ID:

CVE-2022-45826

WordPress Plugin

sunshine-photo-cart <= 2.9.13

Vulnerability Type:

Cross-Site Request Forgery (CSRF),
Missing Authorization

Date:

2022-09-09

The plugin does not have authorisation and Cross-Site Request Forgery (CSRF) check in an AJAX action, which could allow any authenticated users, such as subscriber to copy the gallery files to another folder.

CVE ID:

CVE-2022-3149

WordPress Plugin

wp-custom-cursors <= 3.0.0

Vulnerability Type:

Cross-Site Request Forgery (CSRF),
Cross-Site Scripting (XSS)

Date:

2022-09-07

The plugin does not have Cross-Site Request Forgery (CSRF) check in place when creating and editing cursors, which could allow attackers to made a logged in admin perform such actions via CSRF attacks. Furthermore, due to the lack of sanitisation and escaping in some of the cursor options, it could also lead to Stored Cross-Site Scripting (XSS).

CVE ID:

CVE-2022-3150

WordPress Plugin

wp-custom-cursors <= 3.0.0

Vulnerability Type:

SQL Injection

Date:

2022-09-07

The plugin does not properly sanitize and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by high privileged users such as admin.

CVE ID:

CVE-2022-3151

WordPress Plugin

wp-custom-cursors <= 3.0.0

Vulnerability Type:

Cross-Site Request Forgery (CSRF)

Date:

2022-09-07

The plugin does not have Cross-Site Request Forgery (CSRF) check in place when deleting cursors, which could allow attackers to made a logged in admin delete arbitrary cursors via a Cross-Site Request Forgery (CSRF) attack.

CVE ID:

CVE-2022-3999

WordPress Plugin

woo-shipping-dpd-baltic <= 1.2.57

Vulnerability Type:

Cross-Site Request Forgery (CSRF),
Missing Authorization

Date:

2022-09-07

The plugin does not have authorisation and Cross-Site Request Forgery (CSRF) check in an AJAX action, which could allow any authenticated users, such as subscriber to delete arbitrary options from the blog, which could make the blog unavailable.

CVE ID:

CVE-2022-4000

WordPress Plugin

woo-shipping-dpd-baltic <= 1.2.11

Vulnerability Type:

Cross-Site Scripting (XSS)

Date:

2022-09-07

The plugin does not sanitize and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting (XSS) attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVE ID:

CVE-2022-3420

WordPress Plugin

billingo <= 3.3.9

Vulnerability Type:

Cross-Site Scripting (XSS)

Date:

2022-09-07

The plugin does not sanitize and escape some of its settings, which could allow high privilege users with a role as low as Shop Manager to perform Stored Cross-Site Scripting (XSS) attacks.

CVE ID:

CVE-2022-41685

WordPress Plugin

integration-for-szamlazzhu-woocommerce <= 5.6.3.2

Vulnerability Type:

Cross-Site Request Forgery (CSRF)

Date:

2022-09-07

The plugin is lacking Cross-Site Request Forgery (CSRF) check in various AJAX actions, which could allow attackers to make logged in Shop Managers and above perform unwanted actions, such as deactivate the plugin’s license.

CVE ID:

CVE-2022-41685

WordPress Plugin

hungarian-pickup-points-for-woocommerce <= 1.9.0.2

Vulnerability Type:

Cross-Site Request Forgery (CSRF)

Date:

2022-09-07

The plugin is lacking Cross-Site Request Forgery (CSRF) check in various AJAX actions, which could allow attackers to make logged in Shop Managers and above perform unwanted actions, such as deactivate the plugin’s license.

CVE ID:

CVE-2022-3154

WordPress Plugin

woo-billingo-plus <= 4.4.5.3

Vulnerability Type:

Cross-Site Request Forgery (CSRF)

Date:

2022-09-07

The plugin is lacking Cross-Site Request Forgery (CSRF) check in various AJAX actions, which could allow attackers to make logged in Shop Managers and above perform unwanted actions, such as deactivate the plugin’s license.

CVE ID:

CVE-2022-3154

WordPress Plugin

integration-for-billingo-gravity-forms <= 1.0.3

Vulnerability Type:

Cross-Site Request Forgery (CSRF)

Date:

2022-09-07

The plugin is lacking Cross-Site Request Forgery (CSRF) check in various AJAX actions, which could allow attackers to make logged in Shop Managers and above perform unwanted actions, such as deactivate the plugin’s license.

CVE ID:

CVE-2022-3154

WordPress Plugin

integration-for-szamlazz-hu-gravity-forms <= 1.2.6

Vulnerability Type:

Cross-Site Request Forgery (CSRF)

Date:

2022-09-07

The plugin is lacking Cross-Site Request Forgery (CSRF) check in various AJAX actions, which could allow attackers to make logged in Shop Managers and above perform unwanted actions, such as deactivate the plugin’s license.

CVE ID:

CVE-2022-41990

WordPress Plugin

cardoza-3d-tag-cloud <= 3.8

Vulnerability Type:

Cross-Site Request Forgery (CSRF),
Cross-Site Scripting (XSS)

Date:

2022-09-04

The plugin does not have Cross-Site Request Forgery (CSRF) check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored Cross-Site Scripting (XSS) payloads via a Cross-Site Request Forgery (CSRF) attack.

CVE ID:

CVE-2022-42884

WordPress Plugin

wip-custom-login <= 1.2.6

Vulnerability Type:

Cross-Site Request Forgery (CSRF),
Missing Authorization

Date:

2022-09-01

The plugin does not have authorisation and Cross-Site Request Forgery (CSRF) check when reseting plugin settings, which could allow authenticated users to reset them.