Vulnerabilities > Blazzdev

DATE CVE VULNERABILITY TITLE RISK
2023-12-21 CVE-2023-49765 Authorization Bypass Through User-Controlled Key vulnerability in Blazzdev Rate MY Post
Authorization Bypass Through User-Controlled Key vulnerability in Blaz K.
network
low complexity
blazzdev CWE-639
6.5
2023-01-23 CVE-2022-4673 Unspecified vulnerability in Blazzdev Rate MY Post
The Rate my Post WordPress plugin before 3.3.9 does not validate and escape one of its shortcode attributes, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attack.
network
low complexity
blazzdev
5.4