Plugin

Waiting

5 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.1%
  • Veröffentlicht 20.10.2023 07:15:15
  • Zuletzt bearbeitet 21.11.2024 07:36:19

The Waiting: One-click countdowns plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Countdown name in versions up to, and including, 0.6.2 due to insufficient input sanitization and output escaping. This makes it possible for ...

  • EPSS 0.02%
  • Veröffentlicht 31.08.2023 06:15:10
  • Zuletzt bearbeitet 21.11.2024 08:18:29

The Waiting: One-click countdowns plugin for WordPress is vulnerable to authorization bypass due to missing capability checks on its AJAX calls in versions up to, and including, 0.6.2. This makes it possible for authenticated attackers, with subscrib...

  • EPSS 0.04%
  • Veröffentlicht 31.08.2023 06:15:10
  • Zuletzt bearbeitet 21.11.2024 08:34:11

The Waiting: One-click countdowns plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 0.6.2. This is due to missing or incorrect nonce validation on its AJAX actions. This makes it possible for unauthent...

  • EPSS 0.04%
  • Veröffentlicht 18.05.2023 03:15:11
  • Zuletzt bearbeitet 21.11.2024 07:59:13

The Waiting: One-click countdowns plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on 'saveLang' functions in versions up to, and including, 0.6.2. This could lead to Cross-Site Scripting due to insufficien...

Exploit
  • EPSS 0.45%
  • Veröffentlicht 22.03.2023 21:15:18
  • Zuletzt bearbeitet 25.02.2025 21:15:13

The Waiting: One-click Countdowns WordPress Plugin, version <= 0.6.2, is affected by an authenticated SQL injection vulnerability in the pbc_down[meta][id] parameter of the pbc_save_downs action.