plugin

Mm Breaking News Vulnerabilities

2 known security issues reported for the Mm Breaking News WordPress plugin. Most recent disclosed Aug 22, 2024.

2 medium

Running Mm Breaking News on your site? Check whether your installed version is affected.

Scan your site free

MM-Breaking News <= 0.7.9 - Cross-Site Request Forgery to Stored Cross-Site Scripting

medium

The MM-Breaking News plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 0.7.9. This is due to missing or incorrect nonce validation on a function. This makes it possible for unauthenticated attackers to inject malicious web scripts via a forged request granted they ca...

CVSS:
6.1
Affected:
up to 0.7.9
Fix:
No patched version reported
Disclosed:
Aug 22, 2024

CVE-2024-8054 on NVD →

MM-Breaking News <= 0.7.9 - Reflected Cross-Site Scripting

medium

The MM-Breaking News plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via $_SERVER['REQUEST_URI'] in all versions up to, and including, 0.7.9 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that...

CVSS:
6.1
Affected:
up to 0.7.9
Fix:
No patched version reported
Disclosed:
Aug 22, 2024

CVE-2024-8056 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database