Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Rubina Shaikh

#26623of 53,635
9.6Total CVSS
Vulnerabilities · 2
Medium
2
PT-2022-13147
4.8
2022-03-28
WordPress · Interactive Medical Drawing Of Human Body · CVE-2022-0388
**Name of the Vulnerable Software and Affected Versions** Interactive Medical Drawing of Human Body WordPress plugin versions prior to 2.6 **Description** The issue allows high privilege users to perform Cross-Site Scripting attacks due to the lack of sanitization and escaping of the `Link` field, even when the `unfiltered html` capability is disallowed. **Recommendations** For versions prior to 2.6, update to version 2.6 or later to resolve the issue. As a temporary workaround, consider restricting access to the `Link` field for high privilege users until the update is applied.
PT-2022-13148
4.8
2022-03-07
WordPress · Wp Time Slots Booking Form · CVE-2022-0389
**Name of the Vulnerable Software and Affected Versions** WP Time Slots Booking Form WordPress plugin versions prior to 1.1.63 **Description** The issue allows high privilege users to perform Cross-Site Scripting attacks due to the lack of sanitization and escaping of Calendar names, even when the unfiltered html capability is disallowed. **Recommendations** For versions prior to 1.1.63, update to version 1.1.63 or later to resolve the issue.