Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Hitesh Kumar

#26635of 53,633
9.6Total CVSS
Vulnerabilities · 2
Medium
2
PT-2022-13968
4.8
2022-06-06
WordPress · Drag & Drop Builder · CVE-2022-1569
**Name of the Vulnerable Software and Affected Versions** The Drag & Drop Builder WordPress plugin versions prior to 1.4.9.4 **Description** The issue is related to the lack of sanitization and escaping of some form fields in the plugin, which could allow high privilege users, such as admins, to perform Cross-Site Scripting attacks when unfiltered html is disallowed. **Recommendations** For versions prior to 1.4.9.4, update to version 1.4.9.4 or later to resolve the issue. As a temporary workaround, consider restricting access to the plugin's form fields to minimize the risk of exploitation.
PT-2022-13963
4.8
2022-05-30
10Web · The Form Maker · CVE-2022-1564
**Name of the Vulnerable Software and Affected Versions** The Form Maker by 10Web WordPress plugin versions prior to 1.14.12 **Description** The issue concerns the lack of proper sanitization and escaping of the Custom Text settings in the plugin. This could allow high-privilege users, such as admins, to perform Cross-Site Scripting attacks, even when the unfiltered html capability is disallowed. **Recommendations** For versions prior to 1.14.12, update to version 1.14.12 or later to resolve the issue. As a temporary workaround, consider restricting access to the Custom Text settings to minimize the risk of exploitation.