Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Nithissh Sathish

#18888of 53,633
14.2Total CVSS
Vulnerabilities · 2
Medium
1
High
1
PT-2023-16394
5.4
2023-08-07
WordPress · Wp Food Manager · CVE-2023-0604
**Name of the Vulnerable Software and Affected Versions** WP Food Manager versions prior to 1.0.4 **Description** The issue allows high privilege users, such as admins, to perform Stored Cross-Site Scripting attacks, even when the unfiltered html capability is disallowed, for example in multisite setups. This is due to the plugin not sanitizing and escaping some of its settings. **Recommendations** For versions prior to 1.0.4, update to version 1.0.4 or later to resolve the issue. As a temporary workaround, consider restricting the use of the plugin's settings to minimize the risk of exploitation.
PT-2023-16393
8.8
2023-05-08
WordPress · Sloth Logo Customizer · CVE-2023-0603
**Name of the Vulnerable Software and Affected Versions** Sloth Logo Customizer WordPress plugin versions prior to 2.0.3 **Description** The issue concerns a lack of CSRF check when updating settings, as well as missing sanitization and escaping. This could allow attackers to make logged-in admins add Stored XSS payloads via a CSRF attack. **Recommendations** For Sloth Logo Customizer WordPress plugin versions prior to 2.0.3, update to version 2.0.3 or later to resolve the issue.