Filtered by vendor Wp Survey Plus Project Subscriptions
Filtered by product Wp Survey Plus Subscriptions
Total 1 CVE
CVE Vendors Products Updated CVSS v3.1
CVE-2021-24801 1 Wp Survey Plus Project 1 Wp Survey Plus 2024-08-03 4.3 Medium
The WP Survey Plus WordPress plugin through 1.0 does not have any authorisation and CSRF checks in place in its AJAX actions, allowing any user to call them and add/edit/delete Surveys. Furthermore, due to the lack of sanitization in the Surveys' Title, this could also lead to Stored Cross-Site Scripting issues