Vulnerabilities > Doc4Design

DATE CVE VULNERABILITY TITLE RISK
2019-09-26 CVE-2015-9424 Cross-Site Request Forgery (CSRF) vulnerability in Doc4Design Multicons
The multicons plugin before 3.0 for WordPress has CSRF with resultant XSS via the wp-admin/options-general.php?page=multicons%2Fmulticons.php global_url or admin_url parameter.
network
low complexity
doc4design CWE-352
6.5