Insert Pages Project
Insert Pages Project Insert Pages: vulnerabilidades y CVE
Insert Pages Project Insert Pages tiene 4 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 1 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE4
Últimos 12 meses0
Críticas1
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2022-4483 | Media (5.4) | 0.53% | — | 16 ene 2023 | The Insert Pages WordPress plugin before 3.7.5 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform… |
| CVE-2021-24851 | Media (4.3) | 0.94% | — | 17 nov 2021 | The Insert Pages WordPress plugin before 3.7.0 allows users with a role as low as Contributor to access content and metadata from arbitrary posts/pages regardless of their author and status (ie private), using a… |
| CVE-2021-24850 | Media (5.4) | 0.62% | — | 17 nov 2021 | The Insert Pages WordPress plugin before 3.7.0 adds a shortcode that prints out other pages' content and custom fields. It can be used by users with a role as low as Contributor to perform Cross-Site Scripting attacks… |
| CVE-2017-18586 | Crítica (9.1) | 2.5% | — | 22 ago 2019 | The insert-pages plugin before 3.2.4 for WordPress has directory traversal via custom template paths. |