Vulnerabilities
Vulnerable Software
Wpdeveloper:  Security Vulnerabilities
In the Simple 301 Redirects by BetterLinks WordPress plugin before 2.0.4, the lack of capability checks and insufficient nonce check on the AJAX actions, simple301redirects/admin/get_wildcard and simple301redirects/admin/wildcard, made it possible for authenticated users to retrieve and update the wildcard value for redirects.
CVSS Score
4.3
EPSS Score
0.007
Published
2021-06-14
In the Simple 301 Redirects by BetterLinks WordPress plugin before 2.0.4, a lack of capability checks and insufficient nonce check on the AJAX action, simple301redirects/admin/activate_plugin, made it possible for authenticated users to activate arbitrary plugins installed on vulnerable sites.
CVSS Score
8.8
EPSS Score
0.026
Published
2021-06-14
The Essential Addons for Elementor Lite WordPress Plugin before 4.5.4 has two widgets that are vulnerable to stored Cross-Site Scripting (XSS) by lower-privileged users such as contributors, both via a similar method.
CVSS Score
5.4
EPSS Score
0.006
Published
2021-05-05
The twitter-cards-meta plugin before 2.5.0 for WordPress has XSS.
CVSS Score
6.1
EPSS Score
0.009
Published
2019-08-12
The twitter-cards-meta plugin before 2.5.0 for WordPress has CSRF.
CVSS Score
8.8
EPSS Score
0.007
Published
2019-08-12


Contact Us

Shodan ® - All rights reserved