CVEs (2)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Wp Championship Project 1Wp Championship Jun 17, 2026 Jul 4, 2022 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 The WP Championship WordPress plugin before 9.3 is lacking CSRF checks in various places, allowing attackers to make a logged in admin perform unwanted actions, such as create and delete arbitrary teams as well as update...Show more |
1Wp Championship Project 1Wp Championship May 6, 2026 Nov 2, 2015 N/A· v4 N/A· v3 7.5 HIGH· v2 Multiple SQL injection vulnerabilities in cs_admin_users.php in the wp-championship plugin 5.8 for WordPress allow remote attackers to execute arbitrary SQL commands via the (1) user, (2) isadmin, (3) mail service, (4) m...Show more |