Vulnerabilities > Webinarpress

DATE CVE VULNERABILITY TITLE RISK
2025-01-08 CVE-2024-11270 Missing Authorization vulnerability in Webinarpress
The WordPress Webinar Plugin – WebinarPress plugin for WordPress is vulnerable to arbitrary file creation due to a missing capability check on the 'sync-import-imgs' function and missing file type validation in all versions up to, and including, 1.33.24.
network
low complexity
webinarpress CWE-862
8.8
2025-01-08 CVE-2024-11271 Missing Authorization vulnerability in Webinarpress
The WordPress Webinar Plugin – WebinarPress plugin for WordPress is vulnerable to modification of data due to a missing capability check on several functions in all versions up to, and including, 1.33.24.
network
low complexity
webinarpress CWE-862
4.3
2024-08-26 CVE-2024-43339 Cross-Site Request Forgery (CSRF) vulnerability in Webinarpress
Cross-Site Request Forgery (CSRF) vulnerability in WebinarPress allows Cross-Site Scripting (XSS).This issue affects WebinarPress: from n/a through 1.33.20.
network
low complexity
webinarpress CWE-352
6.1