Vulnerabilities > Cbads

DATE CVE VULNERABILITY TITLE RISK
2021-12-02 CVE-2015-20105 Cross-site Scripting vulnerability in Cbads Clickbank Affiliate ADS
The ClickBank Affiliate Ads WordPress plugin through 1.20 does not have CSRF check when saving its settings, allowing attacker to make logged in admin change them via a CSRF attack.
network
cbads CWE-79
6.8
2021-12-02 CVE-2015-20106 Cross-site Scripting vulnerability in Cbads Clickbank Affiliate ADS
The ClickBank Affiliate Ads WordPress plugin through 1.20 does not escape its settings, allowing high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html is disallowed.
network
cbads CWE-79
3.5