Vulnerabilities (CVE)

Filtered by vendor Weblizar Subscribe
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2021-34628 1 Weblizar 1 Admin Custom Login 2021-08-11 6.8 MEDIUM 8.8 HIGH
The Admin Custom Login WordPress plugin is vulnerable to Cross-Site Request Forgery due to the loginbgSave action found in the ~/includes/Login-form-setting/Login-form-background.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 3.2.7.
CVE-2019-15781 1 Weblizar 1 Social Likebox \& Feed 2019-08-30 6.8 MEDIUM 8.8 HIGH
The facebook-by-weblizar plugin before 2.8.5 for WordPress has CSRF.
CVE-2018-5656 1 Weblizar 1 Pinterest-feeds 2018-01-24 6.8 MEDIUM 8.8 HIGH
An issue was discovered in the weblizar-pinterest-feeds plugin 1.1.1 for WordPress. CSRF exists via wp-admin/admin-ajax.php.