CVE-2021-24615
Wechat Reward <= 1.7 - CSRF to Stored Cross-Site Scripting
The Wechat Reward WordPress plugin through 1.7 does not sanitise or escape its QR settings, nor has any CSRF check in place, allowing attackers to make a logged in admin change the settings and perform Cross-Site Scripting attacks.
Produtos afetados
Unknown · 微信打赏(Wechat Reward)Quer saber se a sua infraestrutura está exposta a isto?
Falar com a TrueHacking →