Wp Custom Cursors Project
wp_custom_cursors_project
4 CVEs • 1 product
Products (1)
Click to collapseToggle
Products (1)
Click to collapse
CVEs (4)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Wp Custom Cursors Project 1Wp Custom Cursors Jun 17, 2026 Jun 19, 2023 N/A· v4 7.2 HIGH· v3 N/A· v2 The WP Custom Cursors WordPress plugin before 3.2 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by users with a role as low as Admin. |
1Wp Custom Cursors Project 1Wp Custom Cursors Jun 17, 2026 Oct 17, 2022 N/A· v4 4.3 MEDIUM· v3 N/A· v2 The WP Custom Cursors WordPress plugin before 3.0.1 does not have CSRF check in place when deleting cursors, which could allow attackers to made a logged in admin delete arbitrary cursors via a CSRF attack. |
1Wp Custom Cursors Project 1Wp Custom Cursors Jun 17, 2026 Oct 17, 2022 N/A· v4 7.2 HIGH· v3 N/A· v2 The WP Custom Cursors WordPress plugin before 3.2 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by high privileged users such as admin |
1Wp Custom Cursors Project 1Wp Custom Cursors Jun 17, 2026 Oct 17, 2022 N/A· v4 6.1 MEDIUM· v3 N/A· v2 The WP Custom Cursors WordPress plugin before 3.0.1 does not have CSRF check in place when creating and editing cursors, which could allow attackers to made a logged in admin perform such actions via CSRF attacks. Furthe...Show more |