← Back

Wsecure

wsecure

Vendor: Joomlaserviceprovider • 2 CVEs

CVEs (2)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Joomlaserviceprovider
1Wsecure
Nov 21, 2024
Sep 4, 2023
N/A· v4
4.8 MEDIUM· v3
N/A· v2
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Ajay Lulia wSecure Lite plugin <= 2.5 versions.
1Joomlaserviceprovider
1Wsecure
Nov 21, 2024
Sep 16, 2019
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
The wsecure plugin before 2.4 for WordPress has remote code execution via shell metacharacters in the wsecure-config.php publish parameter.