Vulnerabilities > Miniorange > Active Directory Integration Ldap Integration > High

DATE CVE VULNERABILITY TITLE RISK
2023-10-16 CVE-2023-5003 Unspecified vulnerability in Miniorange Active Directory Integration / Ldap Integration 3.5.8/3.7.3
The Active Directory Integration / LDAP Integration WordPress plugin before 4.1.10 stores sensitive LDAP logs in a buffer file when an administrator wants to export said logs.
network
low complexity
miniorange
7.5
2023-06-29 CVE-2023-3447 Unspecified vulnerability in Miniorange Active Directory Integration / Ldap Integration
The Active Directory Integration / LDAP Integration plugin for WordPress is vulnerable to LDAP Injection in versions up to, and including, 4.1.5.
network
low complexity
miniorange
7.5
2023-05-15 CVE-2023-0812 Unspecified vulnerability in Miniorange Active Directory Integration / Ldap Integration
The Active Directory Integration / LDAP Integration WordPress plugin before 4.1.1 does not have proper authorization or nonce values for some POST requests, leading to unauthenticated data disclosure.
network
low complexity
miniorange
7.5