2 results (0.003 seconds)

CVSS: 5.4EPSS: 0%CPEs: 1EXPL: 1

The webp-express plugin before 0.14.8 for WordPress has stored XSS. El plugin webp-express anterior a la versión 0.14.8 para WordPress ha almacenado XSS. • https://wordpress.org/plugins/webp-express/#developers https://wpvulndb.com/vulnerabilities/9389 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVSS: 7.5EPSS: 0%CPEs: 1EXPL: 0

The webp-express plugin before 0.14.11 for WordPress has insufficient protection against arbitrary file reading. El plugin webp-express versiones anteriores a 0.14.11 para WordPress, presenta una protección insuficiente contra la lectura arbitraria de archivos. • https://wordpress.org/plugins/webp-express/#developers • CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') •