Autore: Angelo Barbosa

CVE-2015-10131 | chrisy TFO Graphviz Plugin up to 1.9 on WordPress tfo-graphviz-admin.php admin_page_load/admin_page cross site scripting

A vulnerability was found in chrisy TFO Graphviz Plugin up to 1.9 on WordPress and classified as problematic. Affected by this issue is the function admin_page_load/admin_page of the file tfo-graphviz-admin.php. The manipulation leads to cross site scripting. This vulnerability is handled as CVE-2015-10131. The attack may be launched remotely. There is no exploit available. It is recommended to upgrade the affected...

Per saperne di più

CVE-2024-2970 | tsina News Wall Plugin up to 1.1.0 on WordPress Setting nwap_newslist_page cross-site request forgery

A vulnerability has been found in tsina News Wall Plugin up to 1.1.0 on WordPress and classified as problematic. Affected by this vulnerability is the function nwap_newslist_page of the component Setting Handler. The manipulation leads to cross-site request forgery. This vulnerability is known as CVE-2024-2970. The attack can be launched remotely. There is no exploit...

Per saperne di più

CVE-2024-2969 | backie WP-Eggdrop Plugin up to 0.1 on WordPress Setting wpegg_updateOptions cross-site request forgery

A vulnerability, which was classified as problematic, was found in backie WP-Eggdrop Plugin up to 0.1 on WordPress. Affected is the function wpegg_updateOptions of the component Setting Handler. The manipulation leads to cross-site request forgery. This vulnerability is traded as CVE-2024-2969. It is possible to launch the attack remotely. There is no exploit...

Per saperne di più

CVE-2024-2963 | marubon Pocket News Generator Plugin up to 0.2.0 on WordPress Setting Consumer Key/Access Token cross site scripting

A vulnerability, which was classified as problematic, has been found in marubon Pocket News Generator Plugin up to 0.2.0 on WordPress. This issue affects some unknown processing of the component Setting Handler. The manipulation of the argument Consumer Key/Access Token leads to cross site scripting. The identification of this vulnerability is CVE-2024-2963. The attack may be initiated remotely. There is no exploit...

Per saperne di più

CVE-2024-2113 | kstover Ninja Forms Contact Form Plugin up to 3.8.0 on WordPress nf_download_all_subs cross-site request forgery

A vulnerability classified as problematic was found in kstover Ninja Forms Contact Form Plugin up to 3.8.0 on WordPress. This vulnerability affects the function nf_download_all_subs. The manipulation leads to cross-site request forgery. This vulnerability was named CVE-2024-2113. The attack can be initiated remotely. There is no exploit...

Per saperne di più