cleantalk
Vulnerabilities and Security Researches

Vulnerabilities and security researches forwebinar-ignition webinar-ignition

Direction: ascending
Jun 07, 2024

Webinar Solution: Create live/evergreen/automated/instant webinars, stream & Zoom Meetings | WebinarIgnition # CVE-2023-51424

CVE, Research URL

CVE-2023-51424

Date
May 17, 2024
Research Description
Improper Privilege Management vulnerability in Saleswonder Team WebinarIgnition allows Privilege Escalation.This issue affects WebinarIgnition: from n/a through 3.05.0.
Affected versions
Min -, max -.
Status
vulnerable

Webinar Solution: Create live/evergreen/automated/instant webinars, stream & Zoom Meetings | WebinarIgnition # c2729e13130378a765783bf8e120f094aa2a7b8c

Date
Feb 28, 2022
Research Description
Webinar Solution: Create live/evergreen/automated/instant webinars, stream &amp; Zoom Meetings | WebinarIgnition [webinar-ignition] < 2.8.12 (closed) WordPress WebinarIgnition | WordPress Webinar plugin to run live and instant/evergreen/automated/recorded webinars plugin < 2.8.12 - Sensitive Information Disclosure vulnerability Sensitive Information Disclosure vulnerability discovered in WordPress WebinarIgnition | WordPress Webinar plugin to run live and instant/evergreen/automated/recorded webinars plugin (versions < 2.8.12).
Affected versions
Min -, max -.
Status
vulnerable

Webinar Solution: Create live/evergreen/automated/instant webinars, stream &amp; Zoom Meetings | WebinarIgnition # CVE-2023-51423

CVE, Research URL

CVE-2023-51423

Date
Dec 31, 2023
Research Description
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Saleswonder Team Webinar Plugin: Create live/evergreen/automated/instant webinars, stream & Zoom Meetings | WebinarIgnition.This issue affects Webinar Plugin: Create live/evergreen/automated/instant webinars, stream & Zoom Meetings | WebinarIgnition: from n/a through 3.05.0.
Affected versions
Min -, max -.
Status
vulnerable

Webinar Solution: Create live/evergreen/automated/instant webinars, stream &amp; Zoom Meetings | WebinarIgnition # CVE-2023-51422

CVE, Research URL

CVE-2023-51422

Date
Dec 29, 2023
Research Description
Deserialization of Untrusted Data vulnerability in Saleswonder Team Webinar Plugin: Create live/evergreen/automated/instant webinars, stream & Zoom Meetings | WebinarIgnition.This issue affects Webinar Plugin: Create live/evergreen/automated/instant webinars, stream & Zoom Meetings | WebinarIgnition: from n/a through 3.05.0.
Affected versions
Min -, max -.
Status
vulnerable

Webinar Solution: Create live/evergreen/automated/instant webinars, stream &amp; Zoom Meetings | WebinarIgnition # CVE-2024-32445

CVE, Research URL

CVE-2024-32445

Date
Apr 15, 2024
Research Description
Cross-Site Request Forgery (CSRF) vulnerability in Saleswonder Team WebinarIgnition.This issue affects WebinarIgnition: from n/a through 3.05.8.
Affected versions
Min -, max -.
Status
vulnerable
Nov 16, 2024

Webinar Solution: Create live/evergreen/automated/instant webinars, stream &amp; Zoom Meetings | WebinarIgnition # CVE-2022-4974

CVE, Research URL

CVE-2022-4974

Date
Oct 16, 2024
Research Description
The Freemius SDK, as used by hundreds of WordPress plugin and theme developers, was vulnerable to Cross-Site Request Forgery and Information disclosure due to missing capability checks and nonce protection on the _get_debug_log, _get_db_option, and the _set_db_option functions in versions up to, and including 2.4.2. Any WordPress plugin or theme running a version of Freemius less than 2.4.3 is vulnerable.
Affected versions
Min -, max -.
Status
vulnerable
Jul 27, 2025

Webinar Solution: Create live/evergreen/automated/instant webinars, stream &amp; Zoom Meetings | WebinarIgnition # CVE-2025-6441

CVE, Research URL

CVE-2025-6441

Date
Jul 24, 2025
Research Description
The Webinar Solution: Create live/evergreen/automated/instant webinars, stream & Zoom Meetings | WebinarIgnition plugin for WordPress is vulnerable to unauthenticated login token generation due to a missing capability check on the `webinarignition_sign_in_support_staff` and `webinarignition_register_support` functions in all versions up to, and including, 4.03.31. This makes it possible for unauthenticated attackers to generate login tokens for arbitrary WordPress users under certain circumstances, issuing authorization cookies which can lead to authentication bypass.
Affected versions
Min -, max -.
Status
vulnerable