Vulnerabilities > Imagemapper Project
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2023-11-07 | CVE-2023-5506 | Missing Authorization vulnerability in Imagemapper Project Imagemapper 1.2.6 The ImageMapper plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the 'imgmap_delete_area_ajax' function in versions up to, and including, 1.2.6. | 4.3 |
2023-11-07 | CVE-2023-5507 | Cross-site Scripting vulnerability in Imagemapper Project Imagemapper 1.2.6 The ImageMapper plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'imagemap' shortcode in versions up to, and including, 1.2.6 due to insufficient input sanitization and output escaping on user supplied attributes. | 5.4 |
2023-11-07 | CVE-2023-5532 | Cross-Site Request Forgery (CSRF) vulnerability in Imagemapper Project Imagemapper 1.2.6 The ImageMapper plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.2.6. | 4.3 |
2023-11-07 | CVE-2023-5975 | Cross-Site Request Forgery (CSRF) vulnerability in Imagemapper Project Imagemapper 1.2.6 The ImageMapper plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.2.6. | 4.3 |