cleantalk
Vulnerabilities and Security Researches

Vulnerabilities and security researches forattesa-extra attesa-extra

Direction: ascending
Jun 07, 2024

Attesa Extra # CVE-2024-32594

CVE, Research URL

CVE-2024-32594

Application

Attesa Extra

Date
Apr 18, 2024
Research Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in AttesaWP Attesa Extra allows Stored XSS.This issue affects Attesa Extra: from n/a through 1.3.9.
Affected versions
max 1.4.0.
Status
vulnerable
Nov 10, 2024

Attesa Extra # CVE-2024-10688

CVE, Research URL

CVE-2024-10688

Application

Attesa Extra

Date
Nov 09, 2024
Research Description
The Attesa Extra plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 1.4.2 via the 'attesa-template' shortcode due to insufficient restrictions on which posts can be included. This makes it possible for authenticated attackers, with Contributor-level access and above, to extract data from password protected, private, or draft posts that they should not have access to.
Affected versions
max 1.4.3.
Status
vulnerable
Nov 11, 2025

Attesa Extra # CVE-2025-62971

CVE, Research URL

CVE-2025-62971

Application

Attesa Extra

Date
Oct 27, 2025
Research Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CrestaProject Attesa Extra attesa-extra allows Stored XSS.This issue affects Attesa Extra: from n/a through <= 1.4.5.
Affected versions
max 1.4.5.
Status
vulnerable