Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Shweta Mahajan

#26601of 53,639
9.6Total CVSS
Vulnerabilities · 2
Medium
2
PT-2022-13192
4.8
2022-03-07
WordPress · Cp Blocks · CVE-2022-0448
**Name of the Vulnerable Software and Affected Versions** CP Blocks WordPress plugin versions prior to 1.0.15 **Description** The issue allows high privilege users to perform Cross-Site Scripting attacks due to the lack of sanitization and escaping of the `License ID` settings, even when the unfiltered html is disallowed. **Recommendations** For versions prior to 1.0.15, update to version 1.0.15 or later to resolve the issue.
PT-2022-9498
4.8
2022-02-28
WordPress · Security Audit Wordpress Plugin · CVE-2021-24901
**Name of the Vulnerable Software and Affected Versions** Security Audit WordPress plugin version 1.0.0 **Description** The issue allows high privilege users to perform Cross-Site Scripting attacks due to the lack of sanitization and escaping of the `Data Id` setting, even when the `unfiltered html` capability is disallowed. **Recommendations** For Security Audit WordPress plugin version 1.0.0, ensure proper sanitization and escaping of the `Data Id` setting to prevent Cross-Site Scripting attacks. As a temporary workaround, consider restricting the `Data Id` setting to minimize the risk of exploitation.