CVE-2024-32429 – WordPress Remove Footer Credit plugin <= 1.0.13 - Cross Site Scripting (XSS) vulnerability
https://notcve.org/view.php?id=CVE-2024-32429
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPChill Remove Footer Credit allows Stored XSS.This issue affects Remove Footer Credit: from n/a through 1.0.13. La vulnerabilidad de neutralización inadecuada de la entrada durante la generación de páginas web ('Cross-site Scripting') en WPChill Remove Footer Credit permite almacenar XSS. Este problema afecta Quitar crédito de pie de página: desde n/a hasta 1.0.13. The Remove Footer Credit plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 1.0.13 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. • https://patchstack.com/database/vulnerability/remove-footer-credit/wordpress-remove-footer-credit-plugin-1-0-13-cross-site-scripting-xss-vulnerability?_s_id=cve • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •
CVE-2021-25050 – Remove Footer Credit < 1.0.11 - Admin+ Stored Cross-Site Scripting
https://notcve.org/view.php?id=CVE-2021-25050
The Remove Footer Credit WordPress plugin before 1.0.11 does properly sanitise its settings, allowing high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html is disallowed. El plugin Remove Footer Credit de WordPress versiones anteriores a 1.0.11, no sanea correctamente sus parámetros, permitiendo a usuarios con altos privilegios llevar a cabo ataques de tipo Cross-Site Scripting incluso cuando unfiltered_html está deshabilitado • https://plugins.trac.wordpress.org/changeset/2655918 https://wpscan.com/vulnerability/25a28adb-794f-4bdb-89e8-060296b45b38 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •
CVE-2021-24446 – Remove Footer Credit < 1.0.6 - CSRF to Stored Cross-Site Scripting
https://notcve.org/view.php?id=CVE-2021-24446
The Remove Footer Credit WordPress plugin before 1.0.6 does not have CSRF check in place when saving its settings, which could allow attacker to make logged in admins change them and lead to Stored XSS issue as well due to the lack of sanitisation El plugin Remove Footer Credit de WordPress versiones anteriores a 1.0.6, no presenta una comprobación de tipo CSRF cuando guarda sus ajustes, lo que podría permitir a un atacante hacer que administradores registrados los cambien y conllevar a un problema de tipo XSS almacenado debido a una falta de saneo • https://wpscan.com/vulnerability/be55131b-d9f2-4ac1-b667-c544c066887f • CWE-352: Cross-Site Request Forgery (CSRF) •