CVE-2021-25098 – Easy Pricing Tables < 3.1.3 - Arbitrary Post Removal via CSRF
https://notcve.org/view.php?id=CVE-2021-25098
The Pricing Tables WordPress Plugin WordPress plugin before 3.1.3 does not verify the CSRF nonce when removing posts, allowing attackers to make a logged in admin remove arbitrary posts from the blog via a CSRF attack, which will be put in the trash El plugin Pricing Tables de WordPress versiones anteriores a 3.1.3, no verifica el nonce de tipo CSRF cuando son eliminadas entradas, permitiendo a atacantes hacer que un administrador conectado elimine entradas arbitrarias del blog por medio de un ataque de tipo CSRF, que serán depositadas en la papelera • https://wpscan.com/vulnerability/960a634d-a88a-4d90-9ac3-7d24b1fe07fe • CWE-352: Cross-Site Request Forgery (CSRF) •
CVE-2021-24922 – Pixel Cat Lite < 2.6.2 - CSRF to Stored Cross-Site Scripting
https://notcve.org/view.php?id=CVE-2021-24922
The Pixel Cat WordPress plugin before 2.6.2 does not have CSRF check when saving its settings, and did not sanitise as well as escape some of them, which could allow attacker to make a logged in admin change them and perform Cross-Site Scripting attacks El plugin Pixel Cat de WordPress versiones anteriores a 2.6.2, no presenta una comprobación de tipo CSRF al guardar sus configuraciones, y no sanea así como escapa de algunas de ellas, lo que podría permitir a un atacante hacer que un administrador registrado las cambie y realice ataques de tipo Cross-Site Scripting The Pixel Cat – Conversion Pixel Manager WordPress plugin before 2.6.2 does not have CSRF check when saving its settings, and did not sanitise as well as escape some of them, which could allow attacker to make a logged in admin change them and perform Cross-Site Scripting attacks • https://wpscan.com/vulnerability/399ffd65-f3c0-4fbe-a83a-2a620976aad2 • CWE-352: Cross-Site Request Forgery (CSRF) •
CVE-2021-24972 – Pixel Cat Lite < 2.6.3 - Admin+ Stored Cross-Site Scripting
https://notcve.org/view.php?id=CVE-2021-24972
The Pixel Cat WordPress plugin before 2.6.3 does not escape some of its settings, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html is disallowed El plugin Pixel Cat de WordPress versiones anteriores a 2.6.3, no escapa a algunas de sus configuraciones, lo que podría permitir a usuarios muy privilegiados llevar a cabo ataques de tipo Cross-Site Scripting incluso cuando el unfiltered_html está deshabilitado • https://wpscan.com/vulnerability/b960cb36-62de-4b9f-a35d-144a34a4c63d • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •