cleantalk
Vulnerabilities and Security Researches

Vulnerabilities and security researches fordebounce-io-email-validator debounce-io-email-validator

Direction: ascending
Nov 24, 2024

DeBounce Email Validator # CVE-2024-11463

CVE, Research URL

CVE-2024-11463

Date
Nov 23, 2024
Research Description
The DeBounce Email Validator plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'from', 'to', and 'key' parameters in all versions up to, and including, 5.6.5 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.
Affected versions
Min -, max -.
Status
vulnerable
Feb 21, 2025

DeBounce Email Validator # CVE-2024-13339

CVE, Research URL

CVE-2024-13339

Date
Feb 19, 2025
Research Description
The DeBounce Email Validator plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 5.6.6. This is due to missing or incorrect nonce validation on the 'debounce_email_validator' page. This makes it possible for unauthenticated attackers to update settings and inject malicious web scripts via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
Affected versions
Min -, max -.
Status
vulnerable
Apr 05, 2025

DeBounce Email Validator # CVE-2025-31098

CVE, Research URL

CVE-2025-31098

Date
Apr 03, 2025
Research Description
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in debounce DeBounce Email Validator allows PHP Local File Inclusion. This issue affects DeBounce Email Validator: from n/a through 5.7.
Affected versions
Min -, max -.
Status
vulnerable