Vulnerabilities > Thememove

DATE CVE VULNERABILITY TITLE RISK
2022-03-14 CVE-2021-24950 Missing Authorization vulnerability in Thememove Insight Core 1.0
The Insight Core WordPress plugin through 1.0 does not have any authorisation and CSRF checks in the insight_customizer_options_import (available to any authenticated user), does not validate user input before passing it to unserialize(), nor sanitise and escape it before outputting it in the response.
network
thememove CWE-862
3.5