WP Custom Cursors Project
WP Custom Cursors Project WP Custom Cursors: vulnerabilidades y CVE
WP Custom Cursors Project WP Custom Cursors tiene 4 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 0 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE4
Últimos 12 meses0
Críticas0
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2023-2221 | Alta (7.2) | 0.95% | — | 19 jun 2023 | The WP Custom Cursors WordPress plugin before 3.2 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by users with a role as low as Admin. |
| CVE-2022-3151 | Media (4.3) | 0.29% | — | 17 oct 2022 | The WP Custom Cursors WordPress plugin before 3.0.1 does not have CSRF check in place when deleting cursors, which could allow attackers to made a logged in admin delete arbitrary cursors via a CSRF attack. |
| CVE-2022-3150 | Alta (7.2) | 1.0% | — | 17 oct 2022 | The WP Custom Cursors WordPress plugin before 3.2 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by high privileged users such as admin |
| CVE-2022-3149 | Media (6.1) | 0.28% | — | 17 oct 2022 | The WP Custom Cursors WordPress plugin before 3.0.1 does not have CSRF check in place when creating and editing cursors, which could allow attackers to made a logged in admin perform such actions via CSRF attacks.… |