Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
securemoz security audit vulnerabilities and exploits
(subscribe to this query)
6.8
CVSSv2
CVE-2015-6828
The tweet_info function in class/__functions.php in the SecureMoz Security Audit plugin 1.0.5 and previous versions for WordPress does not use an HTTPS session for downloading serialized data, which allows man-in-the-middle malicious users to conduct PHP object injection attacks ...
Securemoz Security Audit
3.5
CVSSv2
CVE-2021-24901
The Security Audit WordPress plugin up to and including 1.0.0 does not sanitise and escape the Data Id setting, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.
Securemoz Security Audit
CVSSv2
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2023-49223
CVE-2024-0044
information disclosure
CVE-2024-35753
HTML injection
CVE-2024-21306
CVE-2024-35733
SQL injection
CVE-2024-35732
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started