WHIZZ < 1.1.1 - Cross-Site Request Forgery
high
The WHIZZ plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to 1.1.1. This is due to missing nonce validation on several different functions. This makes it possible for unauthenticated attackers to delete WordPress users and change the plugin's status via forged requests granted they can t...
- CVSS:
- 8.8
- Affected:
- up to 1.1
- Fixed in:
- 1.1.1
- Disclosed:
- Apr 7, 2017
CVE-2017-8099 on NVD →
WHIZZ < 1.0.8 - Reflected Cross-Site Scripting
medium
Reflected XSS in wordpress plugin whizz v1.0.7 via plugin parameter.
- CVSS:
- 6.1
- Affected:
- up to 1.0.8
- Fixed in:
- 1.0.8
- Disclosed:
- Oct 10, 2016
CVE-2016-1000154 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database