Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total4
Critical0
High0
Medium4
Reset
Showing 1-4 of 4 records
Threat Entry Updated 2025-03-11

CVE-2024-0592 - Related Posts Plugin

The Related Posts for WordPress plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.2.1. This is due to missing or incorrect nonce validation on the handle_create_link() function. This makes it possible for unauthenticated attackers to add related posts to other posts via a forged request granted they can trick a site administrator into performing an action such as clicking on a link. This ultimately makes it possible for attackers to view draft and password protected posts.

PLUGIN Related Posts

CVE-2024-0592

MEDIUM CVSS 5.4 2024-03-13
Threat Entry Updated 2024-11-21

CVE-2022-0594 - Related Posts Plugin

The Professional Social Sharing Buttons, Icons & Related Posts WordPress plugin before 9.7.6 does not have proper authorisation check in one of the AJAX action, available to unauthenticated (in v < 9.7.5) and author+ (in v9.7.5) users, allowing them to call it and retrieve various information such as the list of active plugins, various version like PHP, cURL, WP etc.

PLUGIN Related Posts

CVE-2022-0594

MEDIUM CVSS 5.3 2022-07-25
Threat Entry Updated 2024-11-21

CVE-2021-24482 - Related Posts Plugin

The Related Posts for WordPress plugin through 2.0.4 does not sanitise its heading_text and CSS settings, allowing high privilege users (admin) to set XSS payloads in them, leading to Stored Cross-Site Scripting issues.

PLUGIN Related Posts

CVE-2021-24482

MEDIUM CVSS 4.8 2021-07-19
Threat Entry Updated 2024-11-21

CVE-2021-24180 - Related Posts Plugin

Unvalidated input and lack of output encoding within the Related Posts for WordPress plugin before 2.0.4 lead to a Reflected Cross-Site Scripting (XSS) vulnerability within the 'lang' GET parameter while editing a post, triggered when users with the capability of editing posts access a malicious URL.

PLUGIN Related Posts

CVE-2021-24180

MEDIUM CVSS 5.4 2021-04-05
Scroll to top