Vulnerabilities (CVE)

Join the Common Vulnerabilities and Exposures (CVE) community and start to get notified about new vulnerabilities.

Filtered by vendor Goprayer Subscribe
Filtered by product Wp Prayer
Total 1 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2021-24313 1 Goprayer 1 Wp Prayer 2021-06-11 3.5 LOW 5.4 MEDIUM
The WP Prayer WordPress plugin before 1.6.2 provides the functionality to store requested prayers/praises and list them on a WordPress website. These stored prayer/praise requests can be listed by using the WP Prayer engine. An authenticated WordPress user with any role can fill in the form to request a prayer. The form to request prayers or praises have several fields. The 'prayer request' and 'praise request' fields do not use proper input validation and can be used to store XSS payloads.