Page 5 of 48 results (0.009 seconds)

CVSS: 4.3EPSS: 0%CPEs: 1EXPL: 2

26 May 2021 — In the Simple 301 Redirects by BetterLinks WordPress plugin before 2.0.4, the lack of capability checks and insufficient nonce check on the AJAX actions, simple301redirects/admin/get_wildcard and simple301redirects/admin/wildcard, made it possible for authenticated users to retrieve and update the wildcard value for redirects. En el plugin Simple 301 Redirects by BetterLinks WordPress, versiones anteriores a 2.0.4, una falta de comprobación de capacidad y la comprobación insuficiente de nonce en las accione... • https://wpscan.com/vulnerability/ce8f9648-30fb-4fb9-894e-879dc0f26f98 • CWE-284: Improper Access Control CWE-862: Missing Authorization •

CVSS: 8.8EPSS: 0%CPEs: 1EXPL: 2

26 May 2021 — The import_data function of the Simple 301 Redirects by BetterLinks WordPress plugin before 2.0.4 had no capability or nonce checks making it possible for unauthenticated users to import a set of site redirects. La función import_data del plugin Simple 301 Redirects by BetterLinks WordPress versiones anteriores a 2.0.4, no tenía capacidad ni comprobación de nonce, lo que hacía posible que usuarios no autenticados importaran un conjunto de redireccionamiento del sitio • https://wpscan.com/vulnerability/74c23d56-e81f-47e9-bf8b-33d3f0e81894 • CWE-284: Improper Access Control CWE-862: Missing Authorization •

CVSS: 8.8EPSS: 0%CPEs: 1EXPL: 3

26 May 2021 — In the Simple 301 Redirects by BetterLinks WordPress plugin before 2.0.4, a lack of capability checks and insufficient nonce check on the AJAX action, simple301redirects/admin/activate_plugin, made it possible for authenticated users to activate arbitrary plugins installed on vulnerable sites. En el plugin Simple 301 Redirects by BetterLinks WordPress, versiones anteriores a 2.0.4, una falta de comprobación de capacidad y la insuficiente comprobación de nonce en la acción AJAX, simple301redirects/admin/acti... • https://github.com/RandomRobbieBF/CVE-2021-24356 • CWE-862: Missing Authorization •

CVSS: 8.8EPSS: 0%CPEs: 1EXPL: 2

26 May 2021 — The export_data function of the Simple 301 Redirects by BetterLinks WordPress plugin before 2.0.4 had no capability or nonce checks making it possible for unauthenticated users to export a site's redirects. La función export_data del plugin Simple 301 Redirects by BetterLinks WordPress versiones anteriores a 2.0.4, no tenía capacidad ni comprobaciones de nonce que permitieran a usuarios no autenticados exportar los redireccionamientos del sitio • https://wpscan.com/vulnerability/d770f1fa-7652-465a-833c-b7178146847d • CWE-862: Missing Authorization •

CVSS: 5.4EPSS: 0%CPEs: 1EXPL: 0

13 Apr 2021 — The Essential Addons for Elementor Lite WordPress Plugin before 4.5.4 has two widgets that are vulnerable to stored Cross-Site Scripting (XSS) by lower-privileged users such as contributors, both via a similar method. El Plugin de WordPress Essential Addons for Elementor Lite versiones 4.5.4 presentan dos widgets que son vulnerables a un ataque de tipo Cross-Site Scripting (XSS) almacenado por parte de usuarios menos privilegiados, como contribuyentes, ambos por medio de un método similar • https://wpscan.com/vulnerability/7fb708da-e8c4-4455-b4f9-c4ad72f877da • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVSS: 5.0EPSS: 0%CPEs: 1EXPL: 0

16 Sep 2020 — The NotificationX plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.8.2. This is due to missing or incorrect nonce validation on the generate_conversions() function. This makes it possible for unauthenticated attackers to generate conversions via a forged request granted they can trick a site administrator into performing an action such as clicking on a link. • https://blog.nintechnet.com/25-wordpress-plugins-vulnerable-to-csrf-attacks • CWE-352: Cross-Site Request Forgery (CSRF) •

CVSS: 6.1EPSS: 0%CPEs: 1EXPL: 0

06 Apr 2017 — The twitter-cards-meta plugin before 2.5.0 for WordPress has XSS. El plugin twitter-cards-meta anterior a la versión 2.5.0 para WordPress tiene XSS. The twitter-cards-meta plugin before 2.5.0 for WordPress has XSS via several parameters. • https://wordpress.org/plugins/twitter-cards-meta/#developers • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVSS: 8.8EPSS: 0%CPEs: 1EXPL: 0

06 Apr 2017 — The twitter-cards-meta plugin before 2.5.0 for WordPress has CSRF. El plugin twitter-cards-meta anterior a la versión 2.5.0 para WordPress tiene CSRF. The Twitter Cards Meta plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.4.5. This is due to missing or incorrect nonce validation. This makes it possible for unauthenticated attackers to gain administrative privileges and execute otherwise restricted actions via a forged request granted they can trick a site... • https://wordpress.org/plugins/twitter-cards-meta/#developers • CWE-352: Cross-Site Request Forgery (CSRF) •