Vulnerabilities (CVE)

Filtered by vendor Webfactoryltd Subscribe
Filtered by product External Links In New Window \/ New Tab
Total 2 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2022-1583 1 Webfactoryltd 1 External Links In New Window \/ New Tab 2024-11-21 4.3 MEDIUM 6.5 MEDIUM
The External Links in New Window / New Tab WordPress plugin before 1.43 does not ensure window.opener is set to "null" when links to external sites are clicked, which may enable tabnabbing attacks to occur.
CVE-2022-1582 1 Webfactoryltd 1 External Links In New Window \/ New Tab 2024-11-21 4.3 MEDIUM 6.1 MEDIUM
The External Links in New Window / New Tab WordPress plugin before 1.43 does not properly escape URLs it concatenates to onclick event handlers, which makes Stored Cross-Site Scripting attacks possible.