3 results (0.009 seconds)

CVSS: 8.8EPSS: 0%CPEs: 1EXPL: 0

Cross-Site Request Forgery (CSRF) vulnerability in Brainstorm Force US LLC Schema Pro allows Cross Site Request Forgery.This issue affects Schema Pro: from n/a through 2.7.7. La vulnerabilidad de Cross-Site Request Forgery (CSRF) en Brainstorm Force US LLC Schema Pro permite la Cross-Site Request Forgery. Este problema afecta a Schema Pro: desde n/a hasta 2.7.7. The Schema Pro plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.7.7. This is due to missing or incorrect nonce validation. • https://patchstack.com/database/vulnerability/wp-schema-pro/wordpress-schema-pro-plugin-2-7-7-cross-site-request-forgery-csrf-vulnerability?_s_id=cve • CWE-352: Cross-Site Request Forgery (CSRF) •

CVSS: 8.8EPSS: 0%CPEs: 1EXPL: 0

Cross-Site Request Forgery (CSRF) vulnerability in Brainstorm Force Schema – All In One Schema Rich Snippets plugin <= 1.6.5 versions. The Schema - All In One Schema Rich Snippets plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.6.5. This is due to missing or incorrect nonce validation on the rich_snippet_dashboard function. This makes it possible for unauthenticated attackers to perform unauthorized configuration updates via a forged request granted they can trick a site administrator into performing an action such as clicking on a link. • https://patchstack.com/database/vulnerability/all-in-one-schemaorg-rich-snippets/wordpress-schema-all-in-one-schema-rich-snippets-plugin-1-6-5-cross-site-request-forgery-csrf-vulnerability?_s_id=cve • CWE-352: Cross-Site Request Forgery (CSRF) •

CVSS: 6.1EPSS: 0%CPEs: 1EXPL: 0

The all-in-one-schemaorg-rich-snippets plugin before 1.5.0 for WordPress has XSS on the settings page. El pluginall-in-one-schemaorg-rich-snippets anterior a la versión 1.5.0 para WordPress tiene XSS en la página de configuración. • https://wordpress.org/plugins/all-in-one-schemaorg-rich-snippets/#developers • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •