Vulnerabilities > MOC

DATE CVE VULNERABILITY TITLE RISK
2024-09-17 CVE-2024-8051 Cross-Site Request Forgery (CSRF) vulnerability in MOC Special Feed Items
The Special Feed Items WordPress plugin through 1.0.1 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack.
network
low complexity
moc CWE-352
5.4
2024-09-17 CVE-2024-8052 Cross-Site Request Forgery (CSRF) vulnerability in MOC Review Ratings
The Review Ratings WordPress plugin through 1.6 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack.
network
low complexity
moc CWE-352
6.1