cleantalk
Vulnerabilities and Security Researches

Vulnerabilities and security researches forclickbank-ads-clickbank-widget clickbank-ads-clickbank-widget

Direction: ascending
Jun 07, 2024

Affiliate Ads for ClickBank # CVE-2015-20106

CVE, Research URL

CVE-2015-20106

Date
Dec 02, 2021
Research Description
The ClickBank Affiliate Ads WordPress plugin through 1.20 does not escape its settings, allowing high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html is disallowed.
Affected versions
Min -, max -.
Status
vulnerable

Affiliate Ads for ClickBank # CVE-2015-20105

CVE, Research URL

CVE-2015-20105

Date
Dec 02, 2021
Research Description
The ClickBank Affiliate Ads WordPress plugin through 1.20 does not have CSRF check when saving its settings, allowing attacker to make logged in admin change them via a CSRF attack. Furthermore, due to the lack of escaping when they are outputting, it could also lead to Stored Cross-Site Scripting issues
Affected versions
Min -, max -.
Status
vulnerable