Description
The Quick Subscribe WordPress plugin through 1.7.1 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack and leading to Stored XSS due to the lack of sanitisation and escaping in some of them
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-25072 | The Quick Subscribe WordPress plugin through 1.7.1 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack and leading to Stored XSS due to the lack of sanitisation and escaping in some of them |
References
History
No history.
Status: PUBLISHED
Assigner: WPScan
Published:
Updated: 2024-08-03T00:16:59.933Z
Reserved: 2022-05-18T00:00:00.000Z
Link: CVE-2022-1792
No data.
Status : Modified
Published: 2022-06-13T13:15:13.007
Modified: 2024-11-21T06:41:28.770
Link: CVE-2022-1792
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD