1 results (0.001 seconds)

CVSS: 6.1EPSS: 0%CPEs: 1EXPL: 1

The Migrate Users WordPress plugin through 1.0.1 does not sanitise or escape its Delimiter option before outputting in a page, leading to a Stored Cross-Site Scripting issue. Furthermore, the plugin does not have CSRF check in place when saving its options, allowing the issue to be exploited via a CSRF attack. El plugin Migrate Users WordPress versiones hasta 1.0.1, no sanea ni escapa de su opción Delimiter antes de mostrarla en una página, conllevando a un problema de tipo Cross-Site Scripting Almacenado. Además, el plugin no presenta una comprobación de tipo CSRF cuando guarda sus opciones, permitiendo que el problema sea explotado por medio de un ataque CSRF • https://wpscan.com/vulnerability/7915070f-1d9b-43c3-b01e-fec35f633a4d • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') CWE-352: Cross-Site Request Forgery (CSRF) •