VYPR

Admin Management Xtended

by Admin Management Xtended Project

CVEs (2)

  • CVE-2022-1599MedJul 11, 2022
    risk 0.42cvss 6.5epss 0.01

    The Admin Management Xtended WordPress plugin before 2.4.5 does not have CSRF checks in some of its AJAX actions, allowing attackers to make a logged users with the right capabilities to call them. This can lead to changes in post status (draft, published), slug, post date,…

  • CVE-2015-9390MedSep 20, 2019
    risk 0.28cvss 4.3epss 0.01

    The admin-management-xtended plugin before 2.4.0.1 for WordPress has privilege escalation because wp_ajax functions are mishandled.