« Volver al listado

Marvinlabs

Marvinlabs WP Customer Area: vulnerabilidades y CVE

Marvinlabs WP Customer Area tiene 6 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 0 son críticas y 0 figuran en el catálogo de explotación activa de CISA.

CVE6
Últimos 12 meses0
Críticas0
Explotadas activamente0

Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología

Últimas vulnerabilidades

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2024-12436Media (4.3)0.22%—27 ene 2025
The WP Customer Area WordPress plugin through 8.2.4 does not have CSRF checks in some places, which could allow attackers to make logged in users perform unwanted actions via CSRF attacks
CVE-2024-12280Media (4.3)0.20%—27 ene 2025
The WP Customer Area WordPress plugin through 8.2.4 does not have CSRF check in place when deleting its logs, which could allow attackers to make a logged in to delete them via a CSRF attack
CVE-2024-0665Media (6.1)0.47%—24 ene 2024
The WP Customer Area plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'tab' parameter in all versions up to, and including, 8.2.1 due to insufficient input sanitization and output escaping.…
CVE-2023-6824Media (6.5)0.48%—16 ene 2024
The WP Customer Area WordPress plugin before 8.2.1 does not properly validates user capabilities in some of its AJAX actions, allowing any users to retrieve other user's account address.
CVE-2023-6741Media (4.3)0.39%—16 ene 2024
The WP Customer Area WordPress plugin before 8.2.1 does not properly validate users capabilities in some of its AJAX actions, allowing malicious users to edit other users' account address.
CVE-2017-18519Media (6.1)0.91%—20 ago 2019
The customer-area plugin before 7.4.3 for WordPress has XSS via admin pages.

Otros productos de Marvinlabs