3 results (0.002 seconds)

CVSS: 7.5EPSS: 0%CPEs: 1EXPL: 1

23 Mar 2025 — The Pods WordPress plugin before 3.2.8.2 does not sanitize and escape a parameter before using it in a SQL statement, allowing admins to perform SQL injection attacks • https://wpscan.com/vulnerability/c170fb45-7ed5-40ef-99f6-8da035a23d89 •

CVSS: 6.1EPSS: 0%CPEs: 1EXPL: 1

16 Dec 2024 — The Pods WordPress plugin before 3.2.8.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup). The Pods – Custom Content Types and Fields plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 3.2.8 due to insufficient input sanitization and output escaping.... • https://wpscan.com/vulnerability/85b25a5b-c30b-4a2a-96c1-f05b4eba8a9b • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVSS: 4.8EPSS: 0%CPEs: 1EXPL: 1

15 Oct 2024 — The Pods WordPress plugin before 3.2.7.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup). The Pods – Custom Content Types and Fields plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 3.2.7 due to insufficient input sanitization and output escaping.... • https://wpscan.com/vulnerability/ea4b277e-ef47-4e38-bd82-c5a54a95372f • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •