cleantalk
Vulnerabilities and Security Researches

Vulnerabilities and security researches foradvanced-cron-manager advanced-cron-manager

Direction: descending
May 18, 2025

Advanced Cron Manager – debug & control # CVE-2024-4004

CVE, Research URL

CVE-2024-4004

Date
May 16, 2025
Research Description
The Advanced Cron Manager WordPress plugin before 2.5.7 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)
Affected versions
Min -, max -.
Status
vulnerable
Aug 12, 2024

Advanced Cron Manager – debug & control # CVE-2024-43154

CVE, Research URL

CVE-2024-43154

Date
Nov 01, 2024
Research Description
Missing Authorization vulnerability in BracketSpace Advanced Cron Manager allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Advanced Cron Manager – debug & control: from n/a through 2.5.9.
Affected versions
Min -, max -.
Status
vulnerable
Jun 07, 2024

Advanced Cron Manager – debug & control # CVE-2021-25084

CVE, Research URL

CVE-2021-25084

Date
Feb 07, 2022
Research Description
The Advanced Cron Manager WordPress plugin before 2.4.2 and Advanced Cron Manager Pro WordPress plugin before 2.5.3 do not have authorisation checks in some of their AJAX actions, allowing any authenticated users, such as subscriber to call them and add or remove events as well as schedules for example
Affected versions
Min -, max -.
Status
vulnerable

Advanced Cron Manager – debug & control # CVE-2024-31926

CVE, Research URL

CVE-2024-31926

Date
Apr 11, 2024
Research Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in BracketSpace Advanced Cron Manager – debug & control allows Stored XSS.This issue affects Advanced Cron Manager – debug & control: from n/a through 2.5.2.
Affected versions
Min -, max -.
Status
vulnerable