Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Trang Lkb

#19648of 53,632
13.3Total CVSS
Vulnerabilities · 2
Medium
1
High
1
PT-2022-9590
6.1
2022-02-14
WordPress · Wordpress Newsletter Plugin · CVE-2021-25033
**Name of the Vulnerable Software and Affected Versions** WordPress Newsletter Plugin version 1.6.4 and earlier **Description** The issue is related to an open redirect problem. It occurs because the `to` parameter is not validated before redirecting the user to its given value. **Recommendations** For WordPress Newsletter Plugin version 1.6.4 and earlier, update to version 1.6.5 or later to resolve the issue.
PT-2022-9601
7.2
2022-01-24
WordPress · Asgaros Forum · CVE-2021-25045
**Name of the Vulnerable Software and Affected Versions** Asgaros Forum WordPress plugin versions prior to 1.15.15 **Description** The issue arises from the lack of validation or escaping of the `forum id` parameter before its use in a SQL statement when editing a forum, leading to an SQL injection issue. **Recommendations** For versions prior to 1.15.15, update to version 1.15.15 or later to resolve the issue. As a temporary workaround, consider restricting access to the forum editing functionality to minimize the risk of exploitation.