Vulnerabilities > WP D3 Project
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2023-05-08 | CVE-2023-0536 | Unspecified vulnerability in Wp-D3 Project Wp-D3 The Wp-D3 WordPress plugin through 2.4.1 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks. | 5.4 |
2019-09-13 | CVE-2016-10946 | Cross-Site Request Forgery (CSRF) vulnerability in Wp-D3 Project Wp-D3 The wp-d3 plugin before 2.4.1 for WordPress has CSRF. | 8.8 |