Vulnerabilities > Private Messages Project

DATE CVE VULNERABILITY TITLE RISK
2022-06-15 CVE-2022-29441 Cross-Site Request Forgery (CSRF) vulnerability in Private Messages Project Private Messages
Cross-Site Request Forgery (CSRF) vulnerability in Private Messages For WordPress plugin <= 2.1.10 at WordPress allows attackers to send messages.
4.3
2022-06-15 CVE-2022-29442 Cross-site Scripting vulnerability in Private Messages Project Private Messages
Authenticated (subscriber or higher user role) Stored Cross-Site Scripting (XSS) vulnerability in Messages For WordPress <= 2.1.10 at WordPress.
3.5