Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Dmitry Ingatyev

#34358of 53,633
7.5Total CVSS
Vulnerabilities · 2
Low
1
Medium
1
PT-2025-21440
4.8
2025-05-15
WordPress · Mailpoet · CVE-2024-12743
Name of the Vulnerable Software and Affected Versions: MailPoet WordPress plugin versions prior to 5.5.2 Description: The issue allows high privilege users, such as admins, to perform Stored Cross-Site Scripting attacks. This can occur even when the unfiltered html capability is disallowed, for example in a multisite setup. The problem arises because some settings are not properly sanitised and escaped. Recommendations: For versions prior to 5.5.2, update to version 5.5.2 or later to resolve the issue.
PT-2025-1594
2.7
2025-01-07
10Web · The Form Maker · CVE-2024-10562
**Name of the Vulnerable Software and Affected Versions** The Form Maker by 10Web WordPress plugin versions prior to 1.15.31 **Description** The issue allows high privilege users, such as admin, to perform Stored Cross-Site Scripting attacks even when the unfiltered html capability is disallowed, for example in multisite setup. This is due to the plugin not sanitising and escaping some of its settings. **Recommendations** For versions prior to 1.15.31, update to version 1.15.31 or later to resolve the issue. As a temporary workaround, consider restricting the use of the plugin's settings to minimize the risk of exploitation.