Vulnerabilities > Cbads

DATE CVE VULNERABILITY TITLE RISK
2021-12-02 CVE-2015-20105 Unspecified vulnerability in Cbads Clickbank Affiliate ADS
The ClickBank Affiliate Ads WordPress plugin through 1.20 does not have CSRF check when saving its settings, allowing attacker to make logged in admin change them via a CSRF attack.
network
low complexity
cbads
critical
9.6
2021-12-02 CVE-2015-20106 Unspecified vulnerability in Cbads Clickbank Affiliate ADS
The ClickBank Affiliate Ads WordPress plugin through 1.20 does not escape its settings, allowing high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html is disallowed.
network
low complexity
cbads
4.8