Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Davide Balzano

#47183of 53,632
5.4Total CVSS
Vulnerabilities · 1
PT-2024-36777
5.4
2024-07-13
WordPress · Tournamatch · CVE-2024-5627
**Name of the Vulnerable Software and Affected Versions** Tournamatch WordPress plugin versions prior to 4.6.1 **Description** The issue allows users with a role as low as subscriber to perform Cross-Site Scripting attacks due to the plugin's failure to sanitise and escape some parameters. **Recommendations** For versions prior to 4.6.1, update to version 4.6.1 or later to resolve the issue.