ZeroHour

Vulnerabilities

2 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2017-8099
There is CSRF in the WHIZZ plugin before 1.1.1 for WordPress, allowing attackers to delete any WordPress users and change the plugin's status via a GET request.

There is CSRF in the WHIZZ plugin before 1.1.1 for WordPress, allowing attackers to delete any WordPress users and change the plugin's status via a GET request.

NVD description · AI analysis pending
8.1<1% PoC
  • browserweb inc whizz
CVE-2016-1000154
Reflected XSS in wordpress plugin whizz v1.0.7

Reflected XSS in wordpress plugin whizz v1.0.7

NVD description · AI analysis pending
6.13% PoC
  • browserweb whizz