CVE-2019-15837 – WebP Express <= 0.14.10 - Authenticated Stored Cross-Site Scripting
https://notcve.org/view.php?id=CVE-2019-15837
The webp-express plugin before 0.14.8 for WordPress has stored XSS. El plugin webp-express anterior a la versión 0.14.8 para WordPress ha almacenado XSS. • https://wordpress.org/plugins/webp-express/#developers https://wpvulndb.com/vulnerabilities/9389 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •
CVE-2019-15330 – WebP Express < 0.14.11 - Arbitrary File Read
https://notcve.org/view.php?id=CVE-2019-15330
The webp-express plugin before 0.14.11 for WordPress has insufficient protection against arbitrary file reading. El plugin webp-express versiones anteriores a 0.14.11 para WordPress, presenta una protección insuficiente contra la lectura arbitraria de archivos. • https://wordpress.org/plugins/webp-express/#developers • CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') •