CVE-2023-0824
16.01.2024, 16:15
The User registration & user profile WordPress plugin through 2.0 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged-in admin add Stored XSS payloads via a CSRF attack.
Vendor | Product | Version |
---|---|---|
wpuserplus | userplus | 𝑥 ≤ 2.0 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration