2 results (0.002 seconds)

CVSS: 9.0EPSS: 0%CPEs: 1EXPL: 1

The Pixel Cat WordPress plugin before 2.6.2 does not have CSRF check when saving its settings, and did not sanitise as well as escape some of them, which could allow attacker to make a logged in admin change them and perform Cross-Site Scripting attacks El plugin Pixel Cat de WordPress versiones anteriores a 2.6.2, no presenta una comprobación de tipo CSRF al guardar sus configuraciones, y no sanea así como escapa de algunas de ellas, lo que podría permitir a un atacante hacer que un administrador registrado las cambie y realice ataques de tipo Cross-Site Scripting The Pixel Cat – Conversion Pixel Manager WordPress plugin before 2.6.2 does not have CSRF check when saving its settings, and did not sanitise as well as escape some of them, which could allow attacker to make a logged in admin change them and perform Cross-Site Scripting attacks • https://wpscan.com/vulnerability/399ffd65-f3c0-4fbe-a83a-2a620976aad2 • CWE-352: Cross-Site Request Forgery (CSRF) •

CVSS: 4.8EPSS: 0%CPEs: 1EXPL: 1

The Pixel Cat WordPress plugin before 2.6.3 does not escape some of its settings, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html is disallowed El plugin Pixel Cat de WordPress versiones anteriores a 2.6.3, no escapa a algunas de sus configuraciones, lo que podría permitir a usuarios muy privilegiados llevar a cabo ataques de tipo Cross-Site Scripting incluso cuando el unfiltered_html está deshabilitado • https://wpscan.com/vulnerability/b960cb36-62de-4b9f-a35d-144a34a4c63d • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •