Vulnerabilities
Vulnerable Software
Web-Argument:  Security Vulnerabilities
The Alphabetical List WordPress plugin through 1.0.3 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack
CVSS Score
4.3
EPSS Score
0.0
Published
2024-11-21
Cross-Site Request Forgery (CSRF) vulnerability in Alain Gonzalez plugin <= 3.1.2 versions.
CVSS Score
5.4
EPSS Score
0.001
Published
2023-10-03
The Google Map Shortcode WordPress plugin through 3.1.2 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as admin
CVSS Score
5.4
EPSS Score
0.001
Published
2023-06-19


Contact Us

Shodan ® - All rights reserved