PlugNedit Adaptive Editor < 6.2.0 - Cross-Site Request Forgery leading to Stored Cross-Site Scripting
medium
The PlugNedit Adaptive Editor plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions before 6.2.0. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page via forged request granted they can trick a s...
- CVSS:
- 6.5
- Affected:
- up to 6.2.0
- Fixed in:
- 6.2.0
- Disclosed:
- Aug 25, 2015
CVE-2015-9422 on NVD →
PlugNedit Adaptive Editor < 6.2.0 - Authenticated Stored Cross-Site Scripting
medium
The PlugNedit Adaptive Editor plugin before 6.2.0 for WordPress has Cross-Site Scripting via wp-admin/admin-ajax.php?action=simple_fields_field_type_post_dialog_load PlugneditBGColor, PlugneditEditorMargin, plugnedit_width, pnemedcount, or plugneditcontent parameters due to insufficient input sanitization and output es...
- CVSS:
- 5.4
- Affected:
- up to 6.2.0
- Fixed in:
- 6.2.0
- Disclosed:
- Aug 25, 2015
CVE-2015-9423 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database