Vulnerabilities
Vulnerable Software
Videousermanuals:  >> White Label Cms  Security Vulnerabilities
The White Label CMS WordPress plugin before 2.5 unserializes user input provided via the settings, which could allow high-privilege users such as admin to perform PHP Object Injection when a suitable gadget is present.
CVSS Score
7.2
EPSS Score
0.133
Published
2023-01-02
The White Label CMS WordPress plugin before 2.2.9 does not sanitise and validate the wlcms[_login_custom_js] parameter before outputting it back in the response while previewing, leading to a Reflected Cross-Site Scripting issue
CVSS Score
6.1
EPSS Score
0.113
Published
2022-03-07


Contact Us

Shodan ® - All rights reserved