Active Directory Integration / Ldap Integration
active_directory_integration_/_ldap_integration
Vendor: Miniorange • 6 CVEs
CVEs (6)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Miniorange 1Active Directory Integration / Ldap Integration Apr 23, 2025 Oct 16, 2023 N/A· v4 7.5 HIGH· v3 N/A· v2 The Active Directory Integration / LDAP Integration WordPress plugin before 4.1.10 stores sensitive LDAP logs in a buffer file when an administrator wants to export said logs. Unfortunately, this log file is never remove...Show more |
1Miniorange 1Active Directory Integration / Ldap Integration Apr 8, 2026 Sep 27, 2023 N/A· v4 6.5 MEDIUM· v3 N/A· v2 The Active Directory Integration / LDAP Integration plugin for WordPress is vulnerable to LDAP Passback in versions up to, and including, 4.1.10. This is due to insufficient validation when changing the LDAP server. This...Show more |
1Miniorange 1Active Directory Integration / Ldap Integration Apr 8, 2026 Jun 29, 2023 N/A· v4 7.5 HIGH· v3 N/A· v2 The Active Directory Integration / LDAP Integration plugin for WordPress is vulnerable to LDAP Injection in versions up to, and including, 4.1.5. This is due to insufficient escaping on the supplied username value. This...Show more |
1Miniorange 1Active Directory Integration / Ldap Integration Apr 8, 2026 Jun 9, 2023 N/A· v4 6.5 MEDIUM· v3 N/A· v2 The Active Directory Integration plugin for WordPress is vulnerable to Cross-Site Request Forgery leading to time-based SQL Injection via the orderby and order parameters in versions up to, and including, 4.1.4 due to mi...Show more |
1Miniorange 1Active Directory Integration / Ldap Integration Apr 8, 2026 Jun 9, 2023 N/A· v4 4.9 MEDIUM· v3 N/A· v2 The Active Directory Integration plugin for WordPress is vulnerable to time-based SQL Injection via the orderby and order parameters in versions up to, and including, 4.1.4 due to insufficient escaping on the user suppli...Show more |
1Miniorange 1Active Directory Integration / Ldap Integration Jan 24, 2025 May 15, 2023 N/A· v4 7.5 HIGH· v3 N/A· v2 The Active Directory Integration / LDAP Integration WordPress plugin before 4.1.1 does not have proper authorization or nonce values for some POST requests, leading to unauthenticated data disclosure. |