VM Backups <= 1.0 - Cross-Site Request Forgery to Cross-Site Scripting
high
The VM Backups WordPress plugin through 1.0 does not have CSRF checks, allowing attackers to make a logged in user unwanted actions, such as update the plugin's options, leading to a Stored Cross-Site Scripting issue.
- CVSS:
- 8.8
- Affected:
- up to 1.0
- Fix:
- No patched version reported
- Disclosed:
- Mar 13, 2021
CVE-2021-24173 on NVD →
VM Backups <= 1.0 - Cross-Site Request Forgery
medium
The VM Backups WordPress plugin through 1.0 does not have CSRF checks, allowing attackers to make a logged in user unwanted actions, such as generate backups of the DB, plugins, and current .
- CVSS:
- 4.3
- Affected:
- up to 1.0
- Fix:
- No patched version reported
- Disclosed:
- Mar 13, 2021
CVE-2021-24172 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database