Início
Tendências
Vulnerabilidades
Notícias
Pesquisadores
Por que dbugs?

Tp Cyber Security

Pesquisador dePatchStack
#14371de 53,638
18.7CVSS total
Vulnerabilidades · 2
Alta
1
Crítica
1
PT-2023-30121
9.9
2023-12-29
Tiencop · Wp Extra · CVE-2023-46623
**Name of the Vulnerable Software and Affected Versions** WP EXtra versions n/a through 6.2 **Description** The issue is related to an Improper Control of Generation of Code ('Code Injection') vulnerability in TienCOP WP EXtra. This allows for code injection, which can be exploited by attackers. **Recommendations** For WP EXtra versions n/a through 6.2, update to a version later than 6.2 to resolve the issue. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
PT-2023-29910
8.8
2023-12-18
WordPress · Tiencop Wp Extra · CVE-2023-46212
**Name of the Vulnerable Software and Affected Versions** TienCOP WP EXtra versions n/a through 6.2 **Description** The issue is related to Missing Authorization and Cross-Site Request Forgery (CSRF) in TienCOP WP EXtra, allowing access to functionality not properly constrained by ACLs. This enables Cross Site Request Forgery. **Recommendations** For versions n/a through 6.2, update to a version that properly constrains functionality with ACLs and mitigates CSRF attacks. At the moment, there is no information about a newer version that contains a fix for this vulnerability.