Unknown Wp Prayer vulnerabilities
4 known vulnerabilities affecting unknown/wp_prayer.
Total CVEs
4
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH2MEDIUM2
Vulnerabilities
Page 1 of 1
CVE-2024-3405HIGHCVSS 7.6≤ 2.0.92024-05-15
CVE-2024-3405 [HIGH] CWE-352 CVE-2024-3405: The WP Prayer WordPress plugin through 2.0.9 does not have CSRF check in place when updating its set
The WP Prayer WordPress plugin through 2.0.9 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack
cvelistv5nvd
CVE-2024-3406HIGHCVSS 8.8≤ 2.0.92024-05-15
CVE-2024-3406 [HIGH] CWE-352 CVE-2024-3406: The WP Prayer WordPress plugin through 2.0.9 does not have CSRF check in place when updating its ema
The WP Prayer WordPress plugin through 2.0.9 does not have CSRF check in place when updating its email settings, which could allow attackers to make a logged in admin change them via a CSRF attack
cvelistv5nvd
CVE-2024-3407MEDIUMCVSS 5.3≤ 2.0.92024-05-15
CVE-2024-3407 [MEDIUM] CWE-352 CVE-2024-3407: The WP Prayer WordPress plugin through 2.0.9 does not have CSRF checks in some places, which could a
The WP Prayer WordPress plugin through 2.0.9 does not have CSRF checks in some places, which could allow attackers to make logged in users perform unwanted actions via CSRF attacks
cvelistv5nvd
CVE-2021-24313MEDIUMCVSS 5.4≥ 1.6.2, < 1.6.22021-06-01
CVE-2021-24313 [MEDIUM] CWE-79 CVE-2021-24313: The WP Prayer WordPress plugin before 1.6.2 provides the functionality to store requested prayers/pr
The WP Prayer WordPress plugin before 1.6.2 provides the functionality to store requested prayers/praises and list them on a WordPress website. These stored prayer/praise requests can be listed by using the WP Prayer engine. An authenticated WordPress user with any role can fill in the form to request a prayer. The form to request prayers or praises
cvelistv5nvd