cve,link,title,description,vendor,products,score,severity,epss,cisa,cisa_published,article,ransomware,exploited,poc,trended,trended_no_1,published,trended_score CVE-2024-5943,https://securityvulnerability.io/vulnerability/CVE-2024-5943,Cross-Site Request Forgery Vulnerability in Nested Pages Plugin,"The Nested Pages plugin for WordPress is exposed to a Cross-Site Request Forgery (CSRF) vulnerability due to inadequate nonce validation in the 'settingsPage' function and insufficient sanitization of the 'tab' parameter. This flaw permits unauthorized users to craft requests that can exploit the actions of authenticated users, particularly site administrators. By deceiving an admin into clicking a malicious link, an attacker could leverage this issue to perform unintended actions, undermining the security and integrity of affected WordPress installations.",Wordpress,Nested Pages,8.8,HIGH,0.00044999999227002263,false,,false,false,false,,false,false,2024-07-04T11:34:05.170Z,0 CVE-2023-2434,https://securityvulnerability.io/vulnerability/CVE-2023-2434,Unauthorized Data Loss in Nested Pages Plugin for WordPress,"The Nested Pages plugin for WordPress has a security flaw due to a missing capability check on its 'reset' function. This vulnerability affects versions up to and including 3.2.3, allowing authenticated attackers with editor-level permissions or higher to reset the plugin settings. As a result, these attackers can potentially manipulate or erase critical data, posing significant risks to website integrity and user data security.",Wordpress,Nested Pages,3.8,LOW,0.0009200000204145908,false,,false,false,false,,false,false,2023-05-31T04:15:00.000Z,0 CVE-2022-1990,https://securityvulnerability.io/vulnerability/CVE-2022-1990,Nested Pages < 3.1.21 - Admin+ Stored Cross Site Scripting,"The Nested Pages WordPress plugin before 3.1.21 does not escape and sanitize the some of its settings, which could allow high privilege users to perform Stored Cross-Site Scripting attacks when the unfiltered_html is disallowed",Wordpress,Nested Pages,4.8,MEDIUM,0.000539999979082495,false,,false,false,false,,false,false,2022-06-27T08:59:11.000Z,0 CVE-2021-38342,https://securityvulnerability.io/vulnerability/CVE-2021-38342,Nested Pages <= 3.1.15 Cross-Site Request Forgery to Arbitrary Post Deletion and Modification,"The Nested Pages WordPress plugin <= 3.1.15 was vulnerable to Cross-Site Request Forgery via the `npBulkAction`s and `npBulkEdit` `admin_post` actions, which allowed attackers to trash or permanently purge arbitrary posts as well as changing their status, reassigning their ownership, and editing other metadata.",Wordpress,Nested Pages,8.1,HIGH,0.0005300000193528831,false,,false,false,false,,false,false,2021-08-30T19:15:00.000Z,0 CVE-2021-38343,https://securityvulnerability.io/vulnerability/CVE-2021-38343,Nested Pages <= 3.1.15 Open Redirect,"The Nested Pages WordPress plugin <= 3.1.15 was vulnerable to an Open Redirect via the `page` POST parameter in the `npBulkActions`, `npBulkEdit`, `npListingSort`, and `npCategoryFilter` `admin_post` actions.",Wordpress,Nested Pages,4.7,MEDIUM,0.0010499999625608325,false,,false,false,false,,false,false,2021-08-30T19:15:00.000Z,0