Recall Products <= 0.8 - Authenticated SQL Injection
high
Wordpress Plugin Store / Mike Rooijackers Recall Products V0.8 fails to sanitize input from the 'Manufacturer[]' parameter which allows an authenticated attacker to inject a malicious SQL query.
- CVSS:
- 8.8
- Affected:
- up to 0.8
- Fix:
- No patched version reported
- Disclosed:
- Aug 31, 2020
CVE-2020-25379 on NVD →
Recall Products <= 0.8 - Cross-Site Scripting
medium
Wordpress Plugin Store / Mike Rooijackers Recall Products V0.8 is affected by: Cross Site Scripting (XSS) via the 'Recall Settings' field in admin.php. An attacker can inject JavaScript code that will be stored and executed.
- CVSS:
- 5.4
- Affected:
- up to 0.8
- Fix:
- No patched version reported
- Disclosed:
- Aug 31, 2020
CVE-2020-25380 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database