Vulnerabilities > Webcraftplugins

DATE CVE VULNERABILITY TITLE RISK
2024-10-25 CVE-2024-9584 Missing Authorization vulnerability in Webcraftplugins Image MAP PRO
The Image Map Pro plugin for WordPress is vulnerable to unauthorized modification of data and loss of data due to a missing capability check on the AJAX functions in versions up to, and including, 6.0.20.
network
low complexity
webcraftplugins CWE-862
5.4
2024-10-25 CVE-2024-9585 Cross-site Scripting vulnerability in Webcraftplugins Image MAP PRO
The Image Map Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'save_project' function with an arbitrary shortcode in versions up to, and including, 6.0.20 due to insufficient input sanitization and output escaping on user supplied attributes.
network
low complexity
webcraftplugins CWE-79
5.4