Vulnerabilities (CVE)

Filtered by vendor Wp Survey Plus Project Subscribe
Filtered by product Wp Survey Plus
Total 1 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2021-24801 1 Wp Survey Plus Project 1 Wp Survey Plus 2024-11-21 4.3 MEDIUM 4.3 MEDIUM
The WP Survey Plus WordPress plugin through 1.0 does not have any authorisation and CSRF checks in place in its AJAX actions, allowing any user to call them and add/edit/delete Surveys. Furthermore, due to the lack of sanitization in the Surveys' Title, this could also lead to Stored Cross-Site Scripting issues