Vulnerabilities > Flickrrss Project

DATE CVE VULNERABILITY TITLE RISK
2018-02-06 CVE-2018-6469 Cross-site Scripting vulnerability in Flickrrss Project Flickrrss 5.3.1
A cross-site scripting (XSS) vulnerability in flickrRSS.php in the flickrRSS plugin 5.3.1 for WordPress allows remote attackers to inject arbitrary web script or HTML via the flickrRSS_tags parameter to wp-admin/options-general.php.
network
low complexity
flickrrss-project CWE-79
6.1
2018-02-06 CVE-2018-6468 Cross-site Scripting vulnerability in Flickrrss Project Flickrrss 5.3.1
A cross-site scripting (XSS) vulnerability in flickrRSS.php in the flickrRSS plugin 5.3.1 for WordPress allows remote attackers to inject arbitrary web script or HTML via the flickrRSS_id parameter to wp-admin/options-general.php.
network
low complexity
flickrrss-project CWE-79
6.1
2018-02-06 CVE-2018-6467 Cross-Site Request Forgery (CSRF) vulnerability in Flickrrss Project Flickrrss 5.3.1
The flickrRSS plugin 5.3.1 for WordPress has CSRF via wp-admin/options-general.php.
network
low complexity
flickrrss-project CWE-352
8.8
2018-02-06 CVE-2018-6466 Cross-site Scripting vulnerability in Flickrrss Project Flickrrss 5.3.1
A cross-site scripting (XSS) vulnerability in flickrRSS.php in the flickrRSS plugin 5.3.1 for WordPress allows remote attackers to inject arbitrary web script or HTML via the flickrRSS_set parameter to wp-admin/options-general.php.
network
low complexity
flickrrss-project CWE-79
6.1