Crazy Bone <= 0.6.0 - Unauthenticated Stored Cross-Site Scripting
high
The Crazy Bone WordPress plugin through 0.6.0 does not sanitise and escape the username submitted via the login from when displaying them back in the log dashboard, leading to an unauthenticated Stored Cross-Site scripting
- CVSS:
- 7.2
- Affected:
- up to 0.6.0
- Fix:
- No patched version reported
- Disclosed:
- Jan 31, 2022
CVE-2022-0385 on NVD →
Crazy Bone < 0.6.0 - Stored Cross-Site Scripting
high
The crazy-bone plugin before 0.6.0 for WordPress has XSS via the User-Agent HTTP header
- CVSS:
- 7.2
- Affected:
- up to 0.6.0
- Fixed in:
- 0.6.0
- Disclosed:
- Aug 21, 2015
CVE-2015-9430 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database