Vulnerabilities and security researches forpinterest-pin-it-button-on-image-hover-and-post pinterest-pin-it-button-on-image-hover-and-post
Direction: ascendingJun 06, 2024
Weblizar Pin It Button On Image Hover And Post # ad5d3ba1145a631643e3b54636872587838c3853
- CVE, Research URL
- Application
- Date
- Apr 04, 2022
- Research Description
- Weblizar Pin It Button On Image Hover And Post [pinterest-pin-it-button-on-image-hover-and-post] < 3.4 WordPress Weblizar Pin It Button On Image Hover And Post plugin <= 3.2 - Arbitrary Settings Update vulnerability Arbitrary Settings Update vulnerability discovered by Jan w Oleju in WordPress Weblizar Pin It Button On Image Hover And Post plugin (versions <= 3.2).
- Affected versions
-
max 3.4.
- Status
-
vulnerable
Jun 16, 2026
Weblizar Pin It Button On Image Hover And Post # e3eb806cbcd2fc7656b61a5bba70b0aebb0f9307
- CVE, Research URL
- Application
- Date
- Apr 04, 2022
- Research Description
- Weblizar Pin It Button On Image Hover And Post [pinterest-pin-it-button-on-image-hover-and-post] < 3.4 Weblizar Pin It Button On Image Hover And Post < 3.4 - Authorization Bypass The Weblizar Pin It Button On Image Hover And Post plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the 'SaveSettings' function in versions up to, and including, 3.3. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to change plugin settings.
- Affected versions
-
max 3.4.
- Status
-
vulnerable
Weblizar Pin It Button On Image Hover And Post # 83961cce-646d-494d-a468-f5583ad83688
- CVE, Research URL
- Application
- Date
- -
- Research Description
- Weblizar Pin It Button On Image Hover And Post [pinterest-pin-it-button-on-image-hover-and-post] < 3.4 Weblizar Pin It Button On Image Hover And Post < 3.4 - Subscriber+ Arbitrary Settings Update The plugin does not have authorisation and proper CSRF check when saving its settings, allowing any authenticated users, such as subscribers to update them
- Affected versions
-
max 3.4.
- Status
-
vulnerable