WordPress Bitcoin Payments – Blockonomics <= 3.5.7 - Reflected Cross-Site Scripting
medium
The WordPress Bitcoin Payments – Blockonomics plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘filter_by’ parameter in versions up to, and including, 3.5.7 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary we...
- CVSS:
- 6.1
- Affected:
- up to 3.5.7
- Fixed in:
- 3.5.8
- Disclosed:
- Jan 3, 2023
CVE-2022-47145 on NVD →
WordPress Bitcoin Payments – Blockonomics <= 3.2 - Reflected Cross-Site Scripting
medium
The WordPress Bitcoin Payments – Blockonomics plugin is vulnerable to reflected Cross-Site Scripting via the 'filter_by' parameter in versions before 3.3. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an a...
- CVSS:
- 6.1
- Affected:
- up to 3.3
- Fixed in:
- 3.3
- Disclosed:
- Jun 1, 2021
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database