Vulnerabilities > Webdevocean > WP Quick Frontend Editor > Medium
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2023-06-07 | CVE-2021-4363 | Cross-site Scripting vulnerability in Webdevocean WP Quick Frontend Editor The WP Quick FrontEnd Editor plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 5.5 due to insufficient input sanitization and output escaping on the 'save_content_front' function that uses print_r on the user-supplied $_REQUEST values . | 6.1 |
2023-06-07 | CVE-2021-4378 | Cross-site Scripting vulnerability in Webdevocean WP Quick Frontend Editor The WP Quick FrontEnd Editor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 5.5 due to insufficient input sanitization and output escaping. | 5.4 |
2023-06-07 | CVE-2021-4383 | Missing Authorization vulnerability in Webdevocean WP Quick Frontend Editor The WP Quick FrontEnd Editor plugin for WordPress is vulnerable to page content injection in versions up to, and including, 5.5. | 4.3 |