Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Roguethread

#21799of 53,622
10.9Total CVSS
Vulnerabilities · 2
Medium
2
PT-2022-24713
6.1
2022-12-12
WordPress · Helloprint Wordpress Plugin · CVE-2022-3908
**Name of the Vulnerable Software and Affected Versions** Helloprint WordPress plugin versions prior to 1.4.7 **Description** The issue is related to a Reflected Cross-Site Scripting problem. It occurs because a parameter is not properly sanitised and escaped before being outputted back in the page. **Recommendations** For versions prior to 1.4.7, update to version 1.4.7 or later to resolve the issue. As a temporary workaround, consider restricting access to the plugin until the update is applied.
PT-2022-24715
4.8
2022-12-05
WordPress · Add Comments · CVE-2022-3909
**Name of the Vulnerable Software and Affected Versions** Add Comments WordPress plugin versions 1.0.1 and earlier **Description** The issue allows high privilege users, such as admins, to perform Stored Cross-Site Scripting attacks, even when the unfiltered html capability is disallowed, for example, in a multisite setup. This is due to the plugin not sanitizing and escaping some of its settings. **Recommendations** For Add Comments WordPress plugin versions 1.0.1 and earlier, update to a version that addresses the sanitization and escaping of settings to prevent Stored Cross-Site Scripting attacks. At the moment, there is no information about a newer version that contains a fix for this vulnerability.