Medium 4.3 Unfixed
2026-04-17≤ 3.1.1
Canto <= 3.1.1 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Setting Modification
Minimum safe version
3.0.9
Update to 3.0.9 or later to address 7 fixable vulnerabilities
Canto <= 3.1.1 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Setting Modification
Canto <= 3.1.1 - Missing Authorization to Unauthenticated File Upload
CVE-2024-4936
CVE-2024-25096
CVE-2023-3452
WordPress Canto plugin <= 1.7.0 - Unauthenticated Blind Server-Side Request Forgery (SSRF) vulnerability
Canto <= 1.9.0 - Blind Server-Side Request Forgery via download.php
CVE-2020-28978
CVE-2020-28977
Canto <= 1.9.0 - Blind Server-Side Request Forgery via detail.php