Filtered by vendor Webfactoryltd
Subscribe
Filtered by product External Links In New Window \/ New Tab
Subscribe
Total
2 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2022-1583 | 1 Webfactoryltd | 1 External Links In New Window \/ New Tab | 2024-11-21 | 4.3 MEDIUM | 6.5 MEDIUM |
The External Links in New Window / New Tab WordPress plugin before 1.43 does not ensure window.opener is set to "null" when links to external sites are clicked, which may enable tabnabbing attacks to occur. | |||||
CVE-2022-1582 | 1 Webfactoryltd | 1 External Links In New Window \/ New Tab | 2024-11-21 | 4.3 MEDIUM | 6.1 MEDIUM |
The External Links in New Window / New Tab WordPress plugin before 1.43 does not properly escape URLs it concatenates to onclick event handlers, which makes Stored Cross-Site Scripting attacks possible. |