3 results (0.005 seconds)

CVSS: 5.3EPSS: 0%CPEs: 1EXPL: 0

Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in gVectors Team wpDiscuz allows Code Injection.This issue affects wpDiscuz: from n/a through 7.6.10. Neutralización inadecuada de etiquetas HTML relacionadas con scripts en una vulnerabilidad de página web (XSS básico) en gVectors Team wpDiscuz permite la inyección de código. Este problema afecta a wpDiscuz: desde n/a hasta 7.6.10. The wpDiscuz plugin for WordPress is vulnerable to Arbitrary Content Injection in versions up to, and including, 7.6.10. The cause of this vulnerability is undisclosed at this time. • https://patchstack.com/database/vulnerability/wpdiscuz/wordpress-wpdiscuz-plugin-7-6-10-content-injection-vulnerability?_s_id=cve • CWE-74: Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') CWE-80: Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) •

CVSS: 5.3EPSS: 0%CPEs: 1EXPL: 0

The Comments – wpDiscuz plugin for WordPress is vulnerable to unauthorized modification of data due to insufficient validation on the comment functionality in all versions up to, and including, 7.6.10. This makes it possible for unauthenticated attackers to leave comments on trashed posts. • CWE-862: Missing Authorization •

CVSS: 5.4EPSS: 0%CPEs: 1EXPL: 0

The wpDiscuz plugin for WordPress is vulnerable to unauthorized use of functionality due to a missing capability check on functions corresponding to AJAX actions in versions up to, and including, 7.6.3. This makes it possible for authenticated attackers, with subscriber-level access and above, to view user stats and perform other actions. • CWE-862: Missing Authorization •