Note:
This project will be discontinued after December 13, 2021. [more]
Product:
Simple_add_pages_or_posts
(Mijnpress)Repositories |
Unknown: This might be proprietary software. |
#Vulnerabilities | 2 |
Date | Id | Summary | Products | Score | Patch | Annotated |
---|---|---|---|---|---|---|
2025-02-08 | CVE-2024-13850 | The Simple add pages or posts plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 2.0.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level access, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled. | Simple_add_pages_or_posts | 4.8 | ||
2019-08-14 | CVE-2016-10883 | The simple-add-pages-or-posts plugin before 1.7 for WordPress has CSRF for deleting users. | Simple_add_pages_or_posts | 6.5 |