Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Jan W Oleju

#31028of 53,635
8.3Total CVSS
Vulnerabilities · 2
Medium
2
PT-2024-14945
4.3
2024-04-10
WordPress · Wordpress Ping Optimizer · CVE-2023-6385
**Name of the Vulnerable Software and Affected Versions** WordPress Ping Optimizer plugin versions through 2.35.1.3.0 **Description** The issue concerns the lack of CSRF checks in certain areas, potentially allowing attackers to trick logged-in users into performing unwanted actions, such as clearing logs, via CSRF attacks. **Recommendations** For WordPress Ping Optimizer plugin versions through 2.35.1.3.0, update to a version that includes CSRF checks to prevent such attacks. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
PT-2022-9664
4.0
2022-02-14
WordPress · Futurio Extra · CVE-2021-25109
**Name of the Vulnerable Software and Affected Versions** Futurio Extra WordPress plugin versions prior to 1.6.3 **Description** The issue allows high privilege users to extract data from the database and perform Cross-Site Scripting (XSS) against logged in admins by making them open a malicious link. This is due to a SQL Injection vulnerability. **Recommendations** For versions prior to 1.6.3, update to version 1.6.3 or later to resolve the issue. As a temporary workaround, consider restricting access to the plugin's functionality for high privilege users until the update is applied.