Vulnerabilities
Vulnerable Software
Kreci:  >> Subscribers Text Counter  Security Vulnerabilities
The Subscribers Text Counter WordPress plugin before 1.7.1 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack, which also lead to Stored Cross-Site Scripting due to the lack of sanitisation and escaping
CVSS Score
4.3
EPSS Score
0.001
Published
2023-08-30


Contact Us

Shodan ® - All rights reserved