CVE-2021-24615
Wechat Reward <= 1.7 - CSRF to Stored Cross-Site Scripting
The Wechat Reward WordPress plugin through 1.7 does not sanitise or escape its QR settings, nor has any CSRF check in place, allowing attackers to make a logged in admin change the settings and perform Cross-Site Scripting attacks.
Productos afectados
Unknown · 微信打赏(Wechat Reward)¿Quieres saber si tu infraestructura está expuesta a esto?
Hablar con TrueHacking →