3 results (0.003 seconds)

CVSS: 7.2EPSS: 0%CPEs: 1EXPL: 1

25 Jan 2022 — The Testimonial WordPress Plugin WordPress plugin before 1.4.7 does not validate and escape the id parameter before using it in a SQL statement when retrieving a testimonial to edit, leading to a SQL Injection El plugin Testimonial de WordPress versiones anteriores a 1.4.7, no comprueba ni escapa el parámetro id antes de usarlo en una sentencia SQL cuando es recuperado un testimonio para editarlo, conllevando a una Inyección SQL • https://plugins.trac.wordpress.org/changeset/2664185 • CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') •

CVSS: 6.1EPSS: 0%CPEs: 1EXPL: 1

25 Jan 2022 — The Testimonial WordPress Plugin WordPress plugin before 1.4.7 does not sanitise and escape the id parameter before outputting it back in an attribute, leading to a Reflected cross-Site Scripting El plugin Testimonial WordPress Plugin de WordPress versiones anteriores a 1.4.7, no sanea y escapa el parámetro id antes de devolverlo en un atributo, conllevando a un ataque de tipo cross-Site Scripting Reflejado. The Testimonial WordPress Plugin WordPress plugin before 1.4.7 does not sanitise and escape the id p... • https://plugins.trac.wordpress.org/changeset/2664185 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVSS: 9.8EPSS: 0%CPEs: 93EXPL: 2

13 Oct 2021 — Numerous Plugins and Themes from the AccessPress Themes (aka Access Keys) vendor are backdoored due to their website being compromised. Only plugins and themes downloaded via the vendor website are affected, and those hosted on wordpress.org are not. However, all of them were updated or removed to avoid any confusion Numerosos plugins y temas del proveedor de AccessPress Themes (también se conoce como Access Keys) han sido perjudicados debido a que su sitio web ha sido comprometido. Sólo están afectados los... • https://jetpack.com/2022/01/18/backdoor-found-in-themes-and-plugins-from-accesspress-themes • CWE-912: Hidden Functionality •