Vulnerabilities > Admin Management Xtended Project

DATE CVE VULNERABILITY TITLE RISK
2022-07-11 CVE-2022-1599 Cross-Site Request Forgery (CSRF) vulnerability in Admin Management Xtended Project Admin Management Xtended
The Admin Management Xtended WordPress plugin before 2.4.5 does not have CSRF checks in some of its AJAX actions, allowing attackers to make a logged users with the right capabilities to call them.
network
low complexity
admin-management-xtended-project CWE-352
6.5
2022-06-15 CVE-2022-29450 Cross-Site Request Forgery (CSRF) vulnerability in Admin Management Xtended Project Admin Management Xtended
Multiple Cross-Site Request Forgery (CSRF) vulnerabilities in Admin Management Xtended plugin <= 2.4.4 at WordPress.
network
low complexity
admin-management-xtended-project CWE-352
8.8
2019-09-20 CVE-2015-9390 Improper Privilege Management vulnerability in Admin Management Xtended Project Admin Management Xtended
The admin-management-xtended plugin before 2.4.0.1 for WordPress has privilege escalation because wp_ajax functions are mishandled.
network
low complexity
admin-management-xtended-project CWE-269
4.3