Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Roldan Brandon

#21111of 53,632
11.8Total CVSS
Vulnerabilities · 2
Medium
1
High
1
PT-2022-21896
7.5
2022-07-22
Unknown · Woocommerce · CVE-2022-33901
**Name of the Vulnerable Software and Affected Versions** MultiSafepay plugin for WooCommerce plugin versions <= 4.13.1 **Description** The issue is related to an Unauthenticated Arbitrary File Read vulnerability. This allows unauthorized access to read files. **Recommendations** For versions <= 4.13.1, update to a version higher than 4.13.1 to resolve the issue.
PT-2022-19629
4.3
2022-07-20
Unknown · Wordplus Better Messages · CVE-2022-29454
**Name of the Vulnerable Software and Affected Versions** WordPlus Better Messages plugin versions <= 1.9.9.148 **Description** The issue is related to a Cross-Site Request Forgery (CSRF) vulnerability that allows attackers to upload files when file attachment to messages is activated. **Recommendations** For WordPlus Better Messages plugin versions <= 1.9.9.148, update to a version higher than 1.9.9.148 to resolve the issue. As a temporary workaround, consider deactivating file attachment to messages until a patch is available.