Vulnerabilities > Followmedarling > Spotify Play Button FOR Wordpress

DATE CVE VULNERABILITY TITLE RISK
2023-04-05 CVE-2023-26536 Cross-site Scripting vulnerability in Followmedarling Spotify-Play-Button-For-Wordpress
Auth.
network
low complexity
followmedarling CWE-79
5.4
2023-04-04 CVE-2023-1840 Unspecified vulnerability in Followmedarling Spotify-Play-Button-For-Wordpress
The Sp*tify Play Button for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versions up to, and including, 2.07 due to insufficient input sanitization and output escaping.
network
low complexity
followmedarling
4.8