plugin

St Daily Tip Vulnerabilities

1 known security issue reported for the St Daily Tip WordPress plugin. Most recent disclosed Sep 21, 2021.

1 medium

Running St Daily Tip on your site? Check whether your installed version is affected.

Scan your site free

St Daily Tip <= 4.7 - Cross-Site Request Forgery to Stored Cross-Site Scripting

medium

The St-Daily-Tip WordPress plugin through 4.7 does not have any CSRF check in place when saving its 'Default Text to Display if no tips' setting, and was also lacking sanitisation as well as escaping before outputting it the page. This could allow attacker to make logged in administrators set a malicious payload in it,...

CVSS:
6.1
Affected:
up to 4.7
Fix:
No patched version reported
Disclosed:
Sep 21, 2021

CVE-2021-24487 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database