CVEs (4)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
Cross-Site Request Forgery (CSRF) vulnerability in Kalmang Dynamic Widgets dynamic-widgets.This issue affects Dynamic Widgets: from n/a through <= 1.6.4. |
1Vivwebsolutions 1Dynamic Widgets Nov 27, 2024 Apr 10, 2023 N/A· v4 9.8 CRITICAL· v3 6.5 MEDIUM· v2 A vulnerability, which was classified as critical, has been found in Dynamic Widgets Plugin up to 1.5.10 on WordPress. This issue affects some unknown processing of the file classes/dynwid_class.php. The manipulation lea...Show more |
1Vivwebsolutions 1Dynamic Widgets Nov 27, 2024 Sep 26, 2019 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 The dynamic-widgets plugin before 1.5.11 for WordPress has CSRF with resultant XSS via the wp-admin/themes.php?page=dynwid-config page_limit parameter. |
1Vivwebsolutions 1Dynamic Widgets Nov 27, 2024 Sep 26, 2019 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 The dynamic-widgets plugin before 1.5.11 for WordPress has XSS via the wp-admin/admin-ajax.php?action=term_tree prefix or widget_id parameter. |