NA

CVE-2022-1618

Published: 16/01/2024 Updated: 24/01/2024
CVSS v3 Base Score: 6.1 | Impact Score: 2.7 | Exploitability Score: 2.8
VMScore: 0

Vulnerability Summary

The Coru LFMember WordPress plugin up to and including 1.0.2 does not have CSRF check in place when adding a new game, and is lacking sanitisation as well as escaping in their settings, allowing malicious user to make a logged in admin add an arbitrary game with XSS payloads

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

marcorulicke coru lfmember