➠ CVE-2022-2600 | Auto-hyperlink URLs Plugin up to 5.4.1 on WordPress unknown vulnerability
A vulnerability classified as problematic was found in Auto-hyperlink URLs Plugin up to 5.4.1. Affected by this vulnerability is an unknown functionality. The manipulation leads to use of web link to untrusted target with window.opener access.
This vulnerability is known as CVE-2022-2600. The attack can be launched remotely. There is no exploit available....
vom 1700.87 Punkte User authentication is not properly checked when the WordPress mail is run to prevent stored XSS. Additionally, adding email addresses from post-by-email logs are creating potential for information exposure vulnerability.
This vulnerability affects t
vom 1700.33 Punkte The WordPress HTTP referer is not properly validated when a user is redirected.
This vulnerability affects the following application versions:
WordPress 3.6
WordPress 3.6.1
WordPress 3.7
vom 1697.16 Punkte Missing adequate checks during comment editing can lead to stored XSS attacks.
This vulnerability affects the following application versions:
WordPress 3.6
WordPress 3.6.1
WordPress 3.7
vom 1697.16 Punkte Reset PHPMailer properties between use to prevent information disclosure and revert shared objects for the current user to also prevent information disclosure
This vulnerability affects the following application versions:
WordPress 3.6
vom 1697.16 Punkte Missing authentication settings can lead to CSRF attacks
This vulnerability affects the following application versions:
WordPress 3.6
WordPress 3.6.1
WordPress 3.7
WordPress 3.7.
vom 1634.78 Punkte
Android Auto ist Googles Lösung zur Integration von Android-Smartphones in das Infotainmentsystem eines modernen PKW. Es hat das ältere Mirrorlink längst verdrängt und ist ein Konkurrent zu Carplay, mit dem Apple seine iPhones in das Auto einbindet.
Wir stellen in diesem Artikel alle Aspekte und Var
vom 1621.59 Punkte The plugins screen is not properly escaped to prevent an XSS attack.
This vulnerability affects the following application versions:
WordPress 3.6
WordPress 3.6.1
WordPress 3.7
WordPress 3.7.
vom 1621.05 Punkte The link API in the bookmark is not properly checked against an SQL injection.
This vulnerability affects the following application versions:
WordPress 3.6
WordPress 3.6.1
WordPress 3.7
vom 1621.05 Punkte A variable in the_meta() function is not properly escaped to prevent an XSS attack.
This vulnerability affects the following application versions:
WordPress 3.6
WordPress 3.6.1
WordPress 3.7
vom 1465.66 Punkte The multisite installation of WordPress is not properly sanitized to prevent object injection via the upgrade process.
This vulnerability affects the following application versions:
WordPress 3.6
WordPress 3.6.1
vom 1463.03 Punkte Missing sanitization can lead to SQL injection in WP_Tax_Query
This vulnerability affects the following application versions:
WordPress 3.6
WordPress 3.6.1
WordPress 3.7
WordPress 3.7.
vom 1345.05 Punkte CVE-2020-36326 - An external file could be unexpectedly executable if it was used as a path to an attachment file via PHP's support for .phar files`. Exploitation requires that an attacker was able to provide an unfiltered path to a file to attach.
CVE-2018-19296 - Was vuln
Team Security Diskussion über CVE-2022-2600 | Auto-hyperlink URLs Plugin up to 5.4.1 on WordPress unknown vulnerability