CVE-2023-5411
- EPSS 0.09%
- Veröffentlicht 22.11.2023 16:15:12
- Zuletzt bearbeitet 21.11.2024 08:41:43
The Funnelforms Free plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the fnsf_af2_save_post function in versions up to, and including, 3.4. This makes it possible for authenticated attacker...
CVE-2023-5415
- EPSS 0.09%
- Veröffentlicht 22.11.2023 16:15:12
- Zuletzt bearbeitet 21.11.2024 08:41:43
The Funnelforms Free plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the fnsf_add_category function in versions up to, and including, 3.4. This makes it possible for authenticated attackers...
CVE-2023-5416
- EPSS 0.09%
- Veröffentlicht 22.11.2023 16:15:12
- Zuletzt bearbeitet 21.11.2024 08:41:43
The Funnelforms Free plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the fnsf_delete_category function in versions up to, and including, 3.4. This makes it possible for authenticated attack...
CVE-2023-5417
- EPSS 0.09%
- Veröffentlicht 22.11.2023 16:15:12
- Zuletzt bearbeitet 21.11.2024 08:41:43
The Funnelforms Free plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the fnsf_update_category function in versions up to, and including, 3.4. This makes it possible for authenticated attack...
CVE-2023-5419
- EPSS 0.12%
- Veröffentlicht 22.11.2023 16:15:12
- Zuletzt bearbeitet 21.11.2024 08:41:44
The Funnelforms Free plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the fnsf_af2_test_mail function in versions up to, and including, 3.4. This makes it possible for authenticated attacker...
CVE-2023-5382
- EPSS 0.05%
- Veröffentlicht 22.11.2023 16:15:11
- Zuletzt bearbeitet 21.11.2024 08:41:39
The Funnelforms Free plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.4. This is due to missing or incorrect nonce validation on the fnsf_delete_posts function. This makes it possible for unauthenti...
CVE-2023-5383
- EPSS 0.11%
- Veröffentlicht 22.11.2023 16:15:11
- Zuletzt bearbeitet 21.11.2024 08:41:39
The Funnelforms Free plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.4. This is due to missing or incorrect nonce validation on the fnsf_copy_posts function. This makes it possible for unauthentica...
CVE-2023-5385
- EPSS 0.09%
- Veröffentlicht 22.11.2023 16:15:11
- Zuletzt bearbeitet 21.11.2024 08:41:39
The Funnelforms Free plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the fnsf_copy_posts function in versions up to, and including, 3.4. This makes it possible for authenticated attackers, ...
CVE-2023-5386
- EPSS 0.09%
- Veröffentlicht 22.11.2023 16:15:11
- Zuletzt bearbeitet 21.11.2024 08:41:40
The Funnelforms Free plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the fnsf_delete_posts function in versions up to, and including, 3.4. This makes it possible for authenticated attackers...
CVE-2023-5387
- EPSS 0.09%
- Veröffentlicht 22.11.2023 16:15:11
- Zuletzt bearbeitet 21.11.2024 08:41:40
The Funnelforms Free plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the fnsf_af2_trigger_dark_mode function in versions up to, and including, 3.4. This makes it possible for authenticated ...