Vulnerabilities
4 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2022-0134 +1 in the same advisory: …0279 | The AnyComment WordPress plugin before 0.2.18 does not have CSRF checks in the Import and Revert HyperComments features, allowing attackers to make logged in ad The AnyComment WordPress plugin before 0.2.18 does not have CSRF checks in the Import and Revert HyperComments features, allowing attackers to make logged in admin perform such actions via a CSRF attack NVD description · AI analysis pending | 8.8 group max | <1% | PoC |
| — | |
| CVE-2021-24838 | The AnyComment WordPress plugin before 0.3.5 has an API endpoint which passes user input via the redirect parameter to the wp_redirect() function without being The AnyComment WordPress plugin before 0.3.5 has an API endpoint which passes user input via the redirect parameter to the wp_redirect() function without being validated first, leading to an Open Redirect issue, which according to the vendor, is a feature. NVD description · AI analysis pending | 6.1 | 2% | PoC |
| — | |
| CVE-2018-21001 | The anycomment plugin before 0.0.33 for WordPress has XSS. The anycomment plugin before 0.0.33 for WordPress has XSS. NVD description · AI analysis pending | 6.1 | <1% |
| — |