Wpdevart

Countdown And Countup, Woocommerce Sales Timer

2 vulnerabilities found.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.14%
  • Published 14.11.2023 21:15:11
  • Last modified 21.11.2024 08:30:24

Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in wpdevart Countdown and CountUp, WooCommerce Sales Timer plugin <= 1.8.2 versions.

  • EPSS 0.11%
  • Published 28.09.2021 14:15:07
  • Last modified 21.11.2024 06:10:51

The Countdown and CountUp, WooCommerce Sales Timers WordPress plugin is vulnerable to Cross-Site Request Forgery via the save_theme function found in the ~/includes/admin/coundown_theme_page.php file due to a missing nonce check which allows attacker...