Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Sachin Kumar

#26658of 53,633
9.6Total CVSS
Vulnerabilities · 2
Medium
2
PT-2022-14973
4.8
2022-08-15
WordPress · Duplicate Page/Post · CVE-2022-2152
**Name of the Vulnerable Software and Affected Versions** Duplicate Page and Post WordPress plugin versions prior to 2.8 **Description** The issue allows high privilege users, such as admins, to perform Cross-Site Scripting attacks. This is possible because the plugin does not properly sanitise and escape its settings, even when the unfiltered html capability is disallowed. **Recommendations** For versions prior to 2.8, update to version 2.8 or later to resolve the issue.
PT-2022-15170
4.8
2022-07-17
WordPress · Simple Post Notes · CVE-2022-2186
**Name of the Vulnerable Software and Affected Versions** The Simple Post Notes WordPress plugin versions prior to 1.7.6 **Description** The issue allows high privilege users, such as admins, to perform cross-Site Scripting attacks due to the lack of sanitization and escaping of its settings. This can occur even when the unfiltered html capability is disallowed. **Recommendations** For versions prior to 1.7.6, update to version 1.7.6 or later to resolve the issue. As a temporary workaround, consider restricting access to the plugin's settings for high privilege users until the update is applied.