The dynamic-widgets plugin before 1.5.11 for WordPress...
Moderate severity
Unreviewed
Published
May 24, 2022
to the GitHub Advisory Database
•
Updated Nov 27, 2024
Description
Published by the National Vulnerability Database
Sep 26, 2019
Published to the GitHub Advisory Database
May 24, 2022
Last updated
Nov 27, 2024
The dynamic-widgets plugin before 1.5.11 for WordPress has CSRF with resultant XSS via the wp-admin/themes.php?page=dynwid-config page_limit parameter.
References