CVE-2015-9343
The wp-rollback plugin before 1.2.3 for WordPress has CSRF.
Source: CVE.org
PLUGIN SECURITY
Rollback (or forward) any WordPress.org plugin, theme, or block like a boss.
wp-rollbackDowngradepluginsrevertrollbackversion
2 known CVEs on file for WP Rollback. Reported between 2015 and 2015.
| CVE | Vulnerability | Type | Severity | Affected | Fixed in | Published | Status |
|---|---|---|---|---|---|---|---|
| CVE-2015-9343 | WP Rollback – Rollback Plugins and Themes [wp-rollback] < 1.2.3 | Cross-Site Request Forgery (CSRF) | High 8.8 | < 1.2.3 | 1.2.3 | 2015-06-28 | — |
| CVE-2015-9342 | WP Rollback – Rollback Plugins and Themes [wp-rollback] < 1.2.3 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 6.1 | < 1.2.3 | 1.2.3 | 2015-06-28 | — |
| — | WP Rollback – Rollback Plugins and Themes [wp-rollback] < 1.2.3 | — | Unknown | < 1.2.3 | 1.2.3 | 2015-06-28 | — |
The wp-rollback plugin before 1.2.3 for WordPress has CSRF.
Source: CVE.org
The WP Rollback WordPress plugin was affected by a Cross-Site Scripting (XSS) & CSRF security vulnerability.
Source: WPScan
This plugin is prone to a cross site scripting and cross site request forgery vulnerabilities. Because of XSS vulnerability, the attackers can display any content with no filter from a simple URL, easy to include any remote malicious javascript file. Because of CSRF, anyone can force the installation of any plugin from the repository. Update the plugin.
Source: Patchstack
Update this plugin to the latest release from wordpress.org — each CVE above lists the exact release that fixed it ("Fixed in") when one is on file.
This is the plugin's full known vulnerability history, not a scan of any specific installation — run a free scan of your own site to check your exact installed version.
Run a free passive scan now, or create a free account and install the WP Clinic plugin for a deep scan of your whole hosting account and AI-assisted repair.