← voltar
CVE-2021-24615

Wechat Reward <= 1.7 - CSRF to Stored Cross-Site Scripting

EPSS 0.4%CWE-352CWE-79
The Wechat Reward WordPress plugin through 1.7 does not sanitise or escape its QR settings, nor has any CSRF check in place, allowing attackers to make a logged in admin change the settings and perform Cross-Site Scripting attacks.

Quer saber se a sua infraestrutura está exposta a isto?

Falar com a TrueHacking →