CVE-2023-3356
30.08.2023, 15:15
The Subscribers Text Counter WordPress plugin before 1.7.1 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack, which also lead to Stored Cross-Site Scripting due to the lack of sanitisation and escaping
Vendor | Product | Version |
---|---|---|
kreci | subscribers_text_counter | 𝑥 < 1.7.1 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration