plugin

Whizz Vulnerabilities

2 known security issues reported for the Whizz WordPress plugin. Most recent disclosed Apr 7, 2017.

1 high 1 medium

Running Whizz on your site? Check whether your installed version is affected.

Scan your site free

WHIZZ < 1.1.1 - Cross-Site Request Forgery

high

The WHIZZ plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to 1.1.1. This is due to missing nonce validation on several different functions. This makes it possible for unauthenticated attackers to delete WordPress users and change the plugin's status via forged requests granted they can t...

CVSS:
8.8
Affected:
up to 1.1
Fixed in:
1.1.1
Disclosed:
Apr 7, 2017

CVE-2017-8099 on NVD →

WHIZZ < 1.0.8 - Reflected Cross-Site Scripting

medium

Reflected XSS in wordpress plugin whizz v1.0.7 via plugin parameter.

CVSS:
6.1
Affected:
up to 1.0.8
Fixed in:
1.0.8
Disclosed:
Oct 10, 2016

CVE-2016-1000154 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database