Логотип exploitDog
bind:CVE-2022-2375
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2022-2375

Количество 2

Количество 2

nvd логотип

CVE-2022-2375

больше 3 лет назад

The WP Sticky Button WordPress plugin before 1.4.1 does not have authorisation and CSRF checks when saving its settings, allowing unauthenticated users to update them. Furthermore, due to the lack of escaping in some of them, it could lead to Stored Cross-Site Scripting issues

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-fp9w-4hqx-5jxj

больше 3 лет назад

The WP Sticky Button WordPress plugin before 1.4.1 does not have authorisation and CSRF checks when saving its settings, allowing unauthenticated users to update them. Furthermore, due to the lack of escaping in some of them, it could lead to Stored Cross-Site Scripting issues

CVSS3: 5.4
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2022-2375

The WP Sticky Button WordPress plugin before 1.4.1 does not have authorisation and CSRF checks when saving its settings, allowing unauthenticated users to update them. Furthermore, due to the lack of escaping in some of them, it could lead to Stored Cross-Site Scripting issues

CVSS3: 5.4
0%
Низкий
больше 3 лет назад
github логотип
GHSA-fp9w-4hqx-5jxj

The WP Sticky Button WordPress plugin before 1.4.1 does not have authorisation and CSRF checks when saving its settings, allowing unauthenticated users to update them. Furthermore, due to the lack of escaping in some of them, it could lead to Stored Cross-Site Scripting issues

CVSS3: 5.4
0%
Низкий
больше 3 лет назад

Уязвимостей на страницу