Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Nicolo

#21896of 53,624
10.8Total CVSS
Vulnerabilities · 2
Medium
2
PT-2024-20238
5.4
2024-04-24
WordPress · Better Comments · CVE-2024-2402
**Name of the Vulnerable Software and Affected Versions** Better Comments WordPress plugin versions prior to 1.5.6 **Description** The issue allows high privilege users, such as admins, to perform Stored Cross-Site Scripting attacks, even when the unfiltered html capability is disallowed, for example, in a multisite setup. This is due to the plugin not sanitizing and escaping some of its settings. **Recommendations** For versions prior to 1.5.6, update to version 1.5.6 or later to resolve the issue. As a temporary workaround, consider restricting the ability of high privilege users to modify plugin settings until the update is applied.
PT-2024-20250
5.4
2024-04-24
WordPress · Better Comments · CVE-2024-2404
**Name of the Vulnerable Software and Affected Versions** Better Comments WordPress plugin versions prior to 1.5.6 **Description** The issue allows low privilege users, such as Subscribers, to perform Stored Cross-Site Scripting attacks due to the plugin not sanitizing and escaping some of its settings. **Recommendations** For versions prior to 1.5.6, update to version 1.5.6 or later to resolve the issue. As a temporary workaround, consider restricting access to the plugin's settings for low privilege users until the update is applied.