Vulnerabilities > Admin Management Xtended Project > Admin Management Xtended > Medium
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2022-07-11 | CVE-2022-1599 | Cross-Site Request Forgery (CSRF) vulnerability in Admin Management Xtended Project Admin Management Xtended The Admin Management Xtended WordPress plugin before 2.4.5 does not have CSRF checks in some of its AJAX actions, allowing attackers to make a logged users with the right capabilities to call them. | 6.5 |
2019-09-20 | CVE-2015-9390 | Improper Privilege Management vulnerability in Admin Management Xtended Project Admin Management Xtended The admin-management-xtended plugin before 2.4.0.1 for WordPress has privilege escalation because wp_ajax functions are mishandled. | 4.3 |