cleantalk
Vulnerabilities and Security Researches

Vulnerabilities and security researches forwebinar-ignition webinar-ignition

Direction: ascending
Jun 07, 2024

Webinar Solution: Create live/evergreen/automated/instant webinars, stream & Zoom Meetings | WebinarIgnition # CVE-2023-51424

CVE, Research URL

CVE-2023-51424

Date
May 17, 2024
Research Description
Improper Privilege Management vulnerability in Saleswonder Team WebinarIgnition allows Privilege Escalation.This issue affects WebinarIgnition: from n/a through 3.05.0.
Affected versions
max 3.05.1.
Status
vulnerable

Webinar Solution: Create live/evergreen/automated/instant webinars, stream & Zoom Meetings | WebinarIgnition # c2729e13130378a765783bf8e120f094aa2a7b8c

Date
Feb 28, 2022
Research Description
Webinar Solution: Create live/evergreen/automated/instant webinars, stream &amp; Zoom Meetings | WebinarIgnition [webinar-ignition] < 2.8.12 (closed) WordPress WebinarIgnition | WordPress Webinar plugin to run live and instant/evergreen/automated/recorded webinars plugin < 2.8.12 - Sensitive Information Disclosure vulnerability Sensitive Information Disclosure vulnerability discovered in WordPress WebinarIgnition | WordPress Webinar plugin to run live and instant/evergreen/automated/recorded webinars plugin (versions < 2.8.12).
Affected versions
max 2.8.12.
Status
vulnerable

Webinar Solution: Create live/evergreen/automated/instant webinars, stream &amp; Zoom Meetings | WebinarIgnition # CVE-2023-51423

CVE, Research URL

CVE-2023-51423

Date
Dec 31, 2023
Research Description
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Saleswonder Team Webinar Plugin: Create live/evergreen/automated/instant webinars, stream & Zoom Meetings | WebinarIgnition.This issue affects Webinar Plugin: Create live/evergreen/automated/instant webinars, stream & Zoom Meetings | WebinarIgnition: from n/a through 3.05.0.
Affected versions
max 3.05.1.
Status
vulnerable

Webinar Solution: Create live/evergreen/automated/instant webinars, stream &amp; Zoom Meetings | WebinarIgnition # CVE-2023-51422

CVE, Research URL

CVE-2023-51422

Date
Dec 29, 2023
Research Description
Deserialization of Untrusted Data vulnerability in Saleswonder Team Webinar Plugin: Create live/evergreen/automated/instant webinars, stream & Zoom Meetings | WebinarIgnition.This issue affects Webinar Plugin: Create live/evergreen/automated/instant webinars, stream & Zoom Meetings | WebinarIgnition: from n/a through 3.05.0.
Affected versions
max 3.05.5.
Status
vulnerable

Webinar Solution: Create live/evergreen/automated/instant webinars, stream &amp; Zoom Meetings | WebinarIgnition # CVE-2024-32445

CVE, Research URL

CVE-2024-32445

Date
Apr 15, 2024
Research Description
Cross-Site Request Forgery (CSRF) vulnerability in Saleswonder Team WebinarIgnition.This issue affects WebinarIgnition: from n/a through 3.05.8.
Affected versions
max 3.06.0.
Status
vulnerable
Nov 16, 2024

Webinar Solution: Create live/evergreen/automated/instant webinars, stream &amp; Zoom Meetings | WebinarIgnition # CVE-2022-4974

CVE, Research URL

CVE-2022-4974

Date
Oct 16, 2024
Research Description
The Freemius SDK, as used by hundreds of WordPress plugin and theme developers, was vulnerable to Cross-Site Request Forgery and Information disclosure due to missing capability checks and nonce protection on the _get_debug_log, _get_db_option, and the _set_db_option functions in versions up to, and including 2.4.2. Any WordPress plugin or theme running a version of Freemius less than 2.4.3 is vulnerable.
Affected versions
max 2.8.12.
Status
vulnerable
Jul 27, 2025

Webinar Solution: Create live/evergreen/automated/instant webinars, stream &amp; Zoom Meetings | WebinarIgnition # CVE-2025-6441

CVE, Research URL

CVE-2025-6441

Date
Jul 24, 2025
Research Description
The Webinar Solution: Create live/evergreen/automated/instant webinars, stream & Zoom Meetings | WebinarIgnition plugin for WordPress is vulnerable to unauthenticated login token generation due to a missing capability check on the `webinarignition_sign_in_support_staff` and `webinarignition_register_support` functions in all versions up to, and including, 4.03.32. This makes it possible for unauthenticated attackers to generate login tokens for arbitrary WordPress users under certain circumstances, issuing authorization cookies which can lead to authentication bypass.
Affected versions
max 4.03.33.
Status
vulnerable
Jan 10, 2026

Webinar Solution: Create live/evergreen/automated/instant webinars, stream &amp; Zoom Meetings | WebinarIgnition # CVE-2025-60088

CVE, Research URL

CVE-2025-60088

Date
Dec 18, 2025
Research Description
Missing Authorization vulnerability in Saleswonder Team: Tobias WebinarIgnition webinar-ignition allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WebinarIgnition: from n/a through <= 4.06.04.
Affected versions
max 4.06.04.
Status
vulnerable
May 08, 2026

Webinar Solution: Create live/evergreen/automated/instant webinars, stream &amp; Zoom Meetings | WebinarIgnition # CVE-2026-40797

CVE, Research URL

CVE-2026-40797

Date
May 05, 2026
Research Description
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Saleswonder LLC WebinarIgnition allows Blind SQL Injection. This issue affects WebinarIgnition: from n/a through 4.08.253.
Affected versions
max 4.08.253.
Status
vulnerable