Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total8
Critical0
High0
Medium8
Reset
Showing 1-8 of 8 records
Threat Entry Updated 2024-11-21

CVE-2023-1868 - Yourchannel Plugin

The YourChannel plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check when clearing the plugin cache via the yrc_clear_cache GET parameter in versions up to, and including, 1.2.3. This makes it possible for unauthenticated attackers to clear the plugin's cache.

PLUGIN Yourchannel

CVE-2023-1868

MEDIUM CVSS 6.5 2023-04-05
Threat Entry Updated 2024-11-21

CVE-2023-1865 - Yourchannel Plugin

The YourChannel plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check when resetting plugin settings via the yrc_nuke GET parameter in versions up to, and including, 1.2.3. This makes it possible for unauthenticated attackers to delete YouTube channels from the plugin.

PLUGIN Yourchannel

CVE-2023-1865

MEDIUM CVSS 6.5 2023-04-05
Threat Entry Updated 2024-11-21

CVE-2023-1869 - Yourchannel Plugin

The YourChannel plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versions up to, and including, 1.2.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrative-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.

PLUGIN Yourchannel

CVE-2023-1869

MEDIUM CVSS 5.5 2023-04-05
Threat Entry Updated 2024-11-21

CVE-2023-1871 - Yourchannel Plugin

The YourChannel plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.2.3. This is due to missing or incorrect nonce validation on the deleteLang function. This makes it possible for unauthenticated attackers to reset the plugin's quick language translation settings via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

PLUGIN Yourchannel

CVE-2023-1871

MEDIUM CVSS 5.4 2023-04-05
Threat Entry Updated 2024-11-21

CVE-2023-1867 - Yourchannel Plugin

The YourChannel plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.2.3. This is due to missing or incorrect nonce validation on the save function. This makes it possible for unauthenticated attackers to change the plugin's settings via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

PLUGIN Yourchannel

CVE-2023-1867

MEDIUM CVSS 5.4 2023-04-05
Threat Entry Updated 2024-11-21

CVE-2023-1866 - Yourchannel Plugin

The YourChannel plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.2.3. This is due to missing or incorrect nonce validation on the clearKeys function. This makes it possible for unauthenticated attackers to reset the plugin's channel settings via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

PLUGIN Yourchannel

CVE-2023-1866

MEDIUM CVSS 5.4 2023-04-05
Threat Entry Updated 2024-11-21

CVE-2023-1870 - Yourchannel Plugin

The YourChannel plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.2.3. This is due to missing or incorrect nonce validation on the saveLang function. This makes it possible for unauthenticated attackers to change the plugin's quick language translation settings via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

PLUGIN Yourchannel

CVE-2023-1870

MEDIUM CVSS 4.3 2023-04-05
Threat Entry Updated 2025-03-26

CVE-2023-0282 - Yourchannel Plugin

The YourChannel WordPress plugin before 1.2.2 does not sanitize and escape some parameters, which could allow users with a role as low as Subscriber to perform Cross-Site Scripting attacks.

PLUGIN Yourchannel

CVE-2023-0282

MEDIUM CVSS 5.4 2023-02-06
Scroll to top