Início
Tendências
Vulnerabilidades
Notícias
Pesquisadores
Por que dbugs?

Nithissh Sathish

#18993de 53,779
14.2CVSS total
Vulnerabilidades · 2
Média
1
Alta
1
PT-2023-16394
5.4
2023-08-07
WordPress · Wp Food Manager · CVE-2023-0604
**Name of the Vulnerable Software and Affected Versions** WP Food Manager versions prior to 1.0.4 **Description** The issue allows high privilege users, such as admins, to perform Stored Cross-Site Scripting attacks, even when the unfiltered html capability is disallowed, for example in multisite setups. This is due to the plugin not sanitizing and escaping some of its settings. **Recommendations** For versions prior to 1.0.4, update to version 1.0.4 or later to resolve the issue. As a temporary workaround, consider restricting the use of the plugin's settings to minimize the risk of exploitation.
PT-2023-16393
8.8
2023-05-08
WordPress · Sloth Logo Customizer · CVE-2023-0603
**Name of the Vulnerable Software and Affected Versions** Sloth Logo Customizer WordPress plugin versions prior to 2.0.3 **Description** The issue concerns a lack of CSRF check when updating settings, as well as missing sanitization and escaping. This could allow attackers to make logged-in admins add Stored XSS payloads via a CSRF attack. **Recommendations** For Sloth Logo Customizer WordPress plugin versions prior to 2.0.3, update to version 2.0.3 or later to resolve the issue.