CVE-2023-5745 – Reusable Text Blocks <= 1.5.3 - Authenticated (Author+) Stored Cross-Site Scripting via Shortcode
https://notcve.org/view.php?id=CVE-2023-5745
23 Oct 2023 — The Reusable Text Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'text-blocks' shortcode in versions up to, and including, 1.5.3 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with author-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. El complemento Reusable Text Blocks para WordPress es vulnerable a Cross... • https://plugins.trac.wordpress.org/browser/reusable-text-blocks/tags/1.5.3/text-blocks.php#L319 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •
CVE-2023-22674 – WordPress Dashicons + Custom Post Types Plugin <= 1.0.2 is vulnerable to Broken Access Control
https://notcve.org/view.php?id=CVE-2023-22674
13 Jan 2023 — Missing Authorization, Cross-Site Request Forgery (CSRF) vulnerability in Hal Gatewood Dashicons + Custom Post Types.This issue affects Dashicons + Custom Post Types: from n/a through 1.0.2. Autorización faltante, vulnerabilidad de Cross-Site Request Forgery (CSRF) en Hal Gatewood Dashicons + Custom Post Types. Este problema afecta a Dashicons + Custom Post Types: desde n/a hasta 1.0.2. The Dashicons + Custom Post Types plugin for WordPress is vulnerable to authorization bypass due to a missing capability c... • https://patchstack.com/database/vulnerability/dashicons-cpt/wordpress-dashicons-custom-post-types-plugin-1-0-2-broken-access-control?_s_id=cve • CWE-352: Cross-Site Request Forgery (CSRF) CWE-862: Missing Authorization •