Description
The Clean-Contact WordPress plugin through 1.6 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack and lead to Stored XSS due to the lack of sanitisation and escaping as well
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-25186 | The Clean-Contact WordPress plugin through 1.6 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack and lead to Stored XSS due to the lack of sanitisation and escaping as well |
References
History
No history.
Status: PUBLISHED
Assigner: WPScan
Published:
Updated: 2024-08-03T00:17:00.972Z
Reserved: 2022-05-27T00:00:00.000Z
Link: CVE-2022-1914
No data.
Status : Modified
Published: 2022-06-27T09:15:10.237
Modified: 2024-11-21T06:41:44.567
Link: CVE-2022-1914
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD