Total
2 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2022-2245 | 1 Wow-company | 1 Counter Box | 2022-08-05 | N/A | 8.8 HIGH |
The Counter Box WordPress plugin before 1.2.1 is lacking CSRF check when activating and deactivating counters, which could allow attackers to make a logged in admin perform such actions via CSRF attacks | |||||
CVE-2022-29446 | 1 Wow-company | 1 Counter Box | 2022-05-26 | 4.0 MEDIUM | 7.2 HIGH |
Authenticated (administrator or higher role) Local File Inclusion (LFI) vulnerability in Wow-Company's Counter Box plugin <= 1.1.1 at WordPress. |