CVE-2022-29435 – WordPress Code Snippets Extended plugin <= 1.4.7 - Cross-Site Request Forgery (CSRF) vulnerability
https://notcve.org/view.php?id=CVE-2022-29435
17 May 2022 — Cross-Site Request Forgery (CSRF) vulnerability in Alexander Stokmann's Code Snippets Extended plugin <= 1.4.7 on WordPress allows an attacker to delete or to turn on/off snippets. Una vulnerabilidad de tipo Cross-Site Request Forgery (CSRF) en el plugin Code Snippets Extended de Alexander Stokmann versiones anteriores a 1.4.7 incluyéndola, en WordPress, permite a un atacante eliminar o habilitar/deshabilitar snippets • https://patchstack.com/database/vulnerability/code-snippets-extended/wordpress-code-snippets-extended-plugin-1-4-7-cross-site-request-forgery-csrf-vulnerability • CWE-352: Cross-Site Request Forgery (CSRF) •
CVE-2022-29436 – WordPress Code Snippets Extended plugin <= 1.4.7 - Cross-Site Request Forgery (CSRF) vulnerability leading to Persistent Cross-Site Scripting (XSS)
https://notcve.org/view.php?id=CVE-2022-29436
17 May 2022 — Persistent Cross-Site Scripting (XSS) vulnerability in Alexander Stokmann's Code Snippets Extended plugin <= 1.4.7 on WordPress via Cross-Site Request Forgery (vulnerable parameters &title, &snippet_code). Una vulnerabilidad persistente de tipo Cross-Site Scripting (XSS) en el plugin Code Snippets Extended de Alexander Stokmann versiones anteriores a 1.4.7 incluyéndola, en WordPress, por medio de un ataque de tipo Cross-Site Request Forgery (parámetros vulnerables &title, &snippet_code) • https://patchstack.com/database/vulnerability/code-snippets-extended/wordpress-code-snippets-extended-plugin-1-4-7-cross-site-request-forgery-csrf-vulnerability-leading-to-persistent-cross-site-scripting-xss • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') CWE-352: Cross-Site Request Forgery (CSRF) •
CVE-2022-29429 – WordPress Code Snippets Extended plugin <= 1.4.7 - Cross-Site Request Forgery (CSRF) leading to Remote Code Execution (RCE) vulnerability
https://notcve.org/view.php?id=CVE-2022-29429
04 May 2022 — Remote Code Execution (RCE) in Alexander Stokmann's Code Snippets Extended plugin <= 1.4.7 on WordPress via Cross-Site Request Forgery. Una Ejecución de Código Remota (RCE) en el plugin Code Snippets Extended de Alexander Stokmann versiones anteriores a 1.4.7 incluyéndola, en WordPress, por medio de un ataque de tipo Cross-Site Request Forgery • https://patchstack.com/database/vulnerability/code-snippets-extended/wordpress-code-snippets-extended-plugin-1-4-7-cross-site-request-forgery-csrf-leading-to-remote-code-execution-rce-vulnerability • CWE-352: Cross-Site Request Forgery (CSRF) •