CVE-2023-2351
- EPSS 0.1%
- Veröffentlicht 13.06.2023 02:15:09
- Zuletzt bearbeitet 21.11.2024 07:58:26
The WP Directory Kit plugin for WordPress is vulnerable to unauthorized modification of data and loss of data due to a missing capability check on the 'ajax_admin' function in versions up to, and including, 1.2.3. This makes it possible for authentic...
CVE-2023-2280
- EPSS 0.09%
- Veröffentlicht 09.06.2023 06:16:06
- Zuletzt bearbeitet 21.11.2024 07:58:17
The WP Directory Kit plugin for WordPress is vulnerable to unauthorized modification of data and loss of data due to a missing capability check on the 'ajax_public' function in versions up to, and including, 1.2.2. This makes it possible for unauthen...
CVE-2023-2835
- EPSS 0.68%
- Veröffentlicht 02.06.2023 07:15:09
- Zuletzt bearbeitet 21.11.2024 07:59:23
The WP Directory Kit plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'search' parameter in versions up to, and including, 1.2.3 due to insufficient input sanitization and output escaping. This makes it possible for unauth...