cleantalk
Vulnerabilities and Security Researches

JavaScript Logic, CVE-2024-8090

CVE, Research URL

CVE-2024-8090

Application

JavaScript Logic

Published on
May 16, 2025
Research Description
The JavaScript Logic WordPress plugin through 0.1 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack.
Affected versions
Min -, max 0.1.
Status
vulnerable