The Newsletter, SMTP, Email marketing and Subscribe forms by Sendinblue WordPress plugin before 3.1.25 does not escape the sib-statistics-date parameter before outputting it back in an attribute, leading to a Reflected Cross-Site Scripting issue
CVE-2021-24923
Newsletter, SMTP, Email marketing and Subscribe forms by Sendinblue
Web
Windows
N/A
UNKNOWN
EPSS
0.2%
CVE-2021-24730
Logo Showcase with Slick Slider – Logo Carousel, Logo Slider & Logo Grid
Web
Windows
N/A
UNKNOWN
EPSS
0.1%
The Logo Showcase with Slick Slider WordPress plugin before 1.2.5 does not have CSRF and authorisation checks in the lswss_save_attachment_data AJAX action, allowing any authenticated users, such as Subscriber, to change title, description, alt text, and URL of arbitrary uploaded media.
CVE-2021-24305
Target First Plugin
Web
Windows
N/A
UNKNOWN
EPSS
2.3%
The Target First WordPress Plugin v2.0, also previously known as Watcheezy, suffers from a critical unauthenticated stored XSS vulnerability. An attacker could change the licence key value through a POST on any URL with the 'weeWzKey' parameter that will be save as the 'weeID option and is not sanitized.
← Anterior
Página 69 de 69