Vulnerabilities > Aftabhusain > Medium

DATE CVE VULNERABILITY TITLE RISK
2024-10-22 CVE-2024-9588 Cross-Site Request Forgery (CSRF) vulnerability in Aftabhusain Category and Taxonomy Meta Fields
The Category and Taxonomy Meta Fields plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.0.0.
network
low complexity
aftabhusain CWE-352
5.4
2024-10-22 CVE-2024-9589 Cross-site Scripting vulnerability in Aftabhusain Category and Taxonomy Meta Fields
The Category and Taxonomy Meta Fields plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'new_meta_name' parameter in the 'wpaft_option_page' function in versions up to, and including, 1.0.0 due to insufficient input sanitization and output escaping on user supplied attributes.
network
low complexity
aftabhusain CWE-79
4.8
2024-10-22 CVE-2024-9590 Cross-site Scripting vulnerability in Aftabhusain Category and Taxonomy Meta Fields
The Category and Taxonomy Meta Fields plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the image meta field value in the 'wpaft_add_meta_textinput' function in versions up to, and including, 1.0.0 due to insufficient input sanitization and output escaping on user supplied attributes.
network
low complexity
aftabhusain CWE-79
4.8
2024-10-22 CVE-2024-9591 Cross-site Scripting vulnerability in Aftabhusain Category and Taxonomy Image
The Category and Taxonomy Image plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the '_category_image' parameter in versions up to, and including, 1.0.0 due to insufficient input sanitization and output escaping on user supplied attributes.
network
low complexity
aftabhusain CWE-79
4.8