• 设为首页
  • 点击收藏
  • 手机版
    手机扫一扫访问
    迪恩网络手机版
  • 关注官方公众号
    微信扫一扫关注
    公众号

CVE漏洞

RSS
  • CVE-2022-0827
    CVE-2022-0827
    The Bestbooks WordPress plugin through 2.6.3 does not sanitise and escape some parameters before using them in a SQL statement via an AJAX action, leading to an SQL Injection exploitable by unauthenti ...……
    作者:菜鸟教程小白 | 时间:2022-6-23 09:04 | 阅读:14 | 回复:0
  • CVE-2022-0863
    CVE-2022-0863
    The WP SVG Icons WordPress plugin through 3.2.3 does not properly validate uploaded custom icon packs, allowing an high privileged user like an admin to upload a zip file containing malicious php code ...……
    作者:菜鸟教程小白 | 时间:2022-6-23 09:04 | 阅读:12 | 回复:0
  • CVE-2022-0885
    CVE-2022-0885
    The Member Hero WordPress plugin through 1.0.9 lacks authorization checks, and does not validate the a request parameter in an AJAX action, allowing unauthenticated users to call arbitrary PHP functio ...……
    作者:菜鸟教程小白 | 时间:2022-6-23 09:04 | 阅读:14 | 回复:0
  • CVE-2022-1202
    CVE-2022-1202
    The WP-CRM WordPress plugin through 1.2.1 does not validate and sanitise fields when exporting people to a CSV file, leading to a CSV injection vulnerability.……
    作者:菜鸟教程小白 | 时间:2022-6-23 09:04 | 阅读:14 | 回复:0
  • CVE-2022-1208
    CVE-2022-1208
    The Ultimate Member plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Biography field featured on individual user profile pages due to insufficient input sanitization and outpu ...……
    作者:菜鸟教程小白 | 时间:2022-6-23 09:04 | 阅读:14 | 回复:0
  • CVE-2022-1335
    CVE-2022-1335
    The Slideshow CK WordPress plugin before 1.4.10 does not sanitize and escape Slide's descriptions, which could allow high-privileged users such as admin to perform Cross-Site Scripting attacks whe ...……
    作者:菜鸟教程小白 | 时间:2022-6-23 09:04 | 阅读:14 | 回复:0
  • CVE-2022-1336
    CVE-2022-1336
    The Carousel CK WordPress plugin through 1.1.0 does not sanitize and escape Slide's descriptions, which could allow high-privileged users such as admin to perform Cross-Site Scripting attacks when ...……
    作者:菜鸟教程小白 | 时间:2022-6-23 09:04 | 阅读:12 | 回复:0
  • CVE-2022-1412
    CVE-2022-1412
    The Log WP_Mail WordPress plugin through 0.1 saves sent email in a publicly accessible directory using predictable filenames, allowing any unauthenticated visitor to obtain potentially sensitive infor ...……
    作者:菜鸟教程小白 | 时间:2022-6-23 09:04 | 阅读:10 | 回复:0
  • CVE-2022-1532
    CVE-2022-1532
    Themify WordPress plugin before 1.3.8 does not sanitise and escape the page parameter before outputting it back in an attribute in an admin page, leading to a Reflected Cross-Site Scripting……
    作者:菜鸟教程小白 | 时间:2022-6-23 09:04 | 阅读:9 | 回复:0
  • CVE-2022-1549
    CVE-2022-1549
    The WP Athletics WordPress plugin through 1.1.7 does not sanitize parameters before storing them in the database, nor does it escape the values when outputting them back in the admin dashboard, leadin ...……
    作者:菜鸟教程小白 | 时间:2022-6-23 09:04 | 阅读:8 | 回复:0
  • CVE-2022-1594
    CVE-2022-1594
    The HC Custom WP-Admin URL WordPress plugin through 1.4 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attac ...……
    作者:菜鸟教程小白 | 时间:2022-6-23 09:04 | 阅读:9 | 回复:0
  • CVE-2022-1595
    CVE-2022-1595
    The HC Custom WP-Admin URL WordPress plugin through 1.4 leaks the secret login URL when sending a specific crafted request……
    作者:菜鸟教程小白 | 时间:2022-6-23 09:04 | 阅读:9 | 回复:0
  • CVE-2022-1604
    CVE-2022-1604
    The MailerLite WordPress plugin before 1.5.4 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting……
    作者:菜鸟教程小白 | 时间:2022-6-23 09:04 | 阅读:10 | 回复:0
  • CVE-2022-1605
    CVE-2022-1605
    The Email Users WordPress plugin through 4.8.8 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack and cha ...……
    作者:菜鸟教程小白 | 时间:2022-6-23 09:04 | 阅读:9 | 回复:0
  • CVE-2022-1608
    CVE-2022-1608
    The OnePress Social Locker WordPress plugin through 5.6.2 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF att ...……
    作者:菜鸟教程小白 | 时间:2022-6-23 09:04 | 阅读:11 | 回复:0
  • CVE-2022-1612
    CVE-2022-1612
    The Webriti SMTP Mail WordPress plugin through 1.0 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack……
    作者:菜鸟教程小白 | 时间:2022-6-23 09:04 | 阅读:9 | 回复:0
  • CVE-2022-1624
    CVE-2022-1624
    The Latest Tweets Widget WordPress plugin through 1.1.4 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attac ...……
    作者:菜鸟教程小白 | 时间:2022-6-23 09:04 | 阅读:9 | 回复:0
  • CVE-2022-1656
    CVE-2022-1656
    Vulnerable versions of the JupiterX Theme (=2.0.6) allow any logged-in user, including subscriber-level users, to access any of the functions registered in lib/api/api/ajax.php, which also grant acces ...……
    作者:菜鸟教程小白 | 时间:2022-6-23 09:04 | 阅读:9 | 回复:0
  • CVE-2022-1694
    CVE-2022-1694
    The Useful Banner Manager WordPress plugin through 1.6.1 does not perform CSRF checks on POST requests to its admin page, allowing an attacker to trick a logged in admin to add, modify or delete banne ...……
    作者:菜鸟教程小白 | 时间:2022-6-23 09:04 | 阅读:8 | 回复:0
  • CVE-2022-1707
    CVE-2022-1707
    The Google Tag Manager for WordPress plugin for WordPress is vulnerable to reflected Cross-Site Scripting via the s parameter due to the site search populating into the data layer of sites with insuff ...……
    作者:菜鸟教程小白 | 时间:2022-6-23 09:04 | 阅读:8 | 回复:0
  • CVE-2022-1710
    CVE-2022-1710
    The Appointment Hour Booking WordPress plugin before 1.3.56 does not sanitise and escape a settings of its Calendar fields, which could allow high privilege users to perform Cross-Site Scripting attac ...……
    作者:菜鸟教程小白 | 时间:2022-6-23 09:04 | 阅读:7 | 回复:0
  • CVE-2022-1724
    CVE-2022-1724
    The Simple Membership WordPress plugin before 4.1.1 does not properly sanitise and escape parameters before outputting them back in AJAX actions, leading to Reflected Cross-Site Scripting……
    作者:菜鸟教程小白 | 时间:2022-6-23 09:04 | 阅读:9 | 回复:0
  • CVE-2022-1756
    CVE-2022-1756
    The Newsletter WordPress plugin before 7.4.5 does not sanitize and escape the $_SERVER before echoing it back in admin pages. Although this uses addslashes, and most modern browsers automatically URLE ...……
    作者:菜鸟教程小白 | 时间:2022-6-23 09:04 | 阅读:8 | 回复:0
  • CVE-2022-1758
    CVE-2022-1758
    The Genki Pre-Publish Reminder WordPress plugin through 1.4.1 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF ...……
    作者:菜鸟教程小白 | 时间:2022-6-23 09:04 | 阅读:8 | 回复:0
  • CVE-2022-1759
    CVE-2022-1759
    The RB Internal Links WordPress plugin through 2.0.16 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack, ...……
    作者:菜鸟教程小白 | 时间:2022-6-23 09:04 | 阅读:9 | 回复:0
  • CVE-2022-1761
    CVE-2022-1761
    The Peter’s Collaboration E-mails WordPress plugin through 2.2.0 is vulnerable to CSRF due to missing nonce checks. This allows the change of its settings, which can be used to lower the required ...……
    作者:菜鸟教程小白 | 时间:2022-6-23 09:04 | 阅读:8 | 回复:0
  • CVE-2022-1762
    CVE-2022-1762
    The iQ Block Country WordPress plugin through 1.2.13 does not properly checks HTTP headers in order to validate the origin IP address, allowing threat actors to bypass it's block feature by spoofi ...……
    作者:菜鸟教程小白 | 时间:2022-6-23 09:04 | 阅读:9 | 回复:0
  • CVE-2022-1763
    CVE-2022-1763
    Due to missing checks the Static Page eXtended WordPress plugin through 2.1 is vulnerable to CSRF attacks which allows changing the plugin settings, including required user levels for specific feature ...……
    作者:菜鸟教程小白 | 时间:2022-6-23 09:04 | 阅读:9 | 回复:0
  • CVE-2022-1764
    CVE-2022-1764
    The WP-chgFontSize WordPress plugin through 1.8 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack and le ...……
    作者:菜鸟教程小白 | 时间:2022-6-23 09:04 | 阅读:9 | 回复:0
  • CVE-2022-1765
    CVE-2022-1765
    The Hot Linked Image Cacher WordPress plugin through 1.16 is vulnerable to CSRF. This can be used to store / cache images from external domains on the server, which could lead to legal risks (due to c ...……
    作者:菜鸟教程小白 | 时间:2022-6-23 09:04 | 阅读:9 | 回复:0
  • CVE-2022-1772
    CVE-2022-1772
    The Google Places Reviews WordPress plugin before 2.0.0 does not properly escape its Google API key setting, which is reflected on the site's administration panel. A malicious administrator could ...……
    作者:菜鸟教程小白 | 时间:2022-6-23 09:04 | 阅读:9 | 回复:0
  • CVE-2022-1773
    CVE-2022-1773
    The WP Athletics WordPress plugin through 1.1.7 does not sanitise and escape a parameter before outputting back in an admin page, leading to a Reflected Cross-Site Scripting……
    作者:菜鸟教程小白 | 时间:2022-6-23 09:04 | 阅读:8 | 回复:0
  • CVE-2022-1777
    CVE-2022-1777
    The Filr WordPress plugin before 1.2.2.1 does not have authorisation check in two of its AJAX actions, allowing them to be called by any authenticated users, such as subscriber. They are are protected ...……
    作者:菜鸟教程小白 | 时间:2022-6-23 09:04 | 阅读:8 | 回复:0
  • CVE-2022-1779
    CVE-2022-1779
    The Auto Delete Posts WordPress plugin through 1.3.0 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack a ...……
    作者:菜鸟教程小白 | 时间:2022-6-23 09:04 | 阅读:9 | 回复:0
  • CVE-2022-1780
    CVE-2022-1780
    The LaTeX for WordPress plugin through 3.4.10 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack which co ...……
    作者:菜鸟教程小白 | 时间:2022-6-23 09:04 | 阅读:11 | 回复:0
  • CVE-2022-1781
    CVE-2022-1781
    The postTabs WordPress plugin through 2.10.6 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack, which al ...……
    作者:菜鸟教程小白 | 时间:2022-6-23 09:04 | 阅读:10 | 回复:0
  • CVE-2022-1787
    CVE-2022-1787
    The Sideblog WordPress plugin through 6.0 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack and lead to ...……
    作者:菜鸟教程小白 | 时间:2022-6-23 09:04 | 阅读:12 | 回复:0
  • CVE-2022-1788
    CVE-2022-1788
    Due to missing checks the Change Uploaded File Permissions WordPress plugin through 4.0.0 is vulnerable to CSRF attacks. This can be used to change the file and folder permissions of any folder. This ...……
    作者:菜鸟教程小白 | 时间:2022-6-23 09:04 | 阅读:14 | 回复:0
  • CVE-2022-1790
    CVE-2022-1790
    The New User Email Set Up WordPress plugin through 0.5.2 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF atta ...……
    作者:菜鸟教程小白 | 时间:2022-6-23 09:04 | 阅读:14 | 回复:0
  • CVE-2022-1791
    CVE-2022-1791
    The One Click Plugin Updater WordPress plugin through 2.4.14 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF ...……
    作者:菜鸟教程小白 | 时间:2022-6-23 09:04 | 阅读:12 | 回复:0

关注我们

极客给你想要的成长

关注极客中国获取最新资讯

热门推荐
专题导读
阅读排行榜

扫描微信二维码

查看手机版网站

随时了解更新最新资讯

139-2527-9053

在线客服(服务时间 9:00~18:00)

在线QQ客服
地址:深圳市南山区西丽大学城创智工业园
电邮:jeky_zhao#qq.com
移动电话:139-2527-9053

Powered by 互联科技 X3.4© 2001-2213 极客世界.|Sitemap