Security
Headlines
HeadlinesLatestCVEs

Headline

CVE-2023-2450: Diff from ajax-search-for-woocommerce/tags/1.23.0@2917453 to ajax-search-for-woocommerce/tags/1.24.0@2917453 – WordPress Plugin Repository

The FiboSearch - AJAX Search for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versions up to, and including, 1.23.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.

CVE
#xss#web#wordpress#auth

Changeset view not shown, since the total size (5.3 MB) exceeds 4.0 MB

Note: See TracChangeset for help on using the changeset viewer.

CVE: Latest News

CVE-2023-50976: Transactions API Authorization by oleiman · Pull Request #14969 · redpanda-data/redpanda
CVE-2023-6905
CVE-2023-6903
CVE-2023-6904
CVE-2023-3907