Medium 6.3
2024-10-16< 3.3.11
Freemius SDK <= 2.4.2 - Missing Authorization Checks
Minimum safe version
5.2.10
Update to 5.2.10 or later to address 10 fixable vulnerabilities
Freemius SDK <= 2.4.2 - Missing Authorization Checks
CVE-2024-43921
CVE-2024-6724
WordPress Magic Post Thumbnail Plugin < 4.1.13 is vulnerable to Cross Site Scripting (XSS)
Magic Post Thumbnail < 3.3.7 - Reflected Cross-Site Scripting (XSS)
CVE-2023-29171
Magic Post Thumbnail <= 3.3.6 - Reflected Cross-Site Scripting
Freemius SDK <= 2.4.2 - Missing Authorization Checks
WordPress Magic Post Thumbnail plugin < 3.3.11 - Sensitive Information Disclosure vulnerability
WordPress Magic Post Thumbnail plugin < 3.3.11 - Toggle The Debug Mode via Cross-Site Request Forgery (CSRF) vulnerability