Vulnerabilities > WP Master

DATE CVE VULNERABILITY TITLE RISK
2023-03-20 CVE-2023-25795 Cross-site Scripting vulnerability in Wp-Master Feed Changer & Remover 0.1/0.2
Auth.
network
low complexity
wp-master CWE-79
4.8
2023-01-23 CVE-2022-4307 Unspecified vulnerability in Wp-Master Pardakht-Delkhah
The ?????? ?????? ?????? WordPress plugin before 2.9.3 does not sanitise and escape some parameters, allowing unauthenticated attackers to send a request with XSS payloads, which will be triggered when a high privilege users such as admin visits a page from the plugin.
network
low complexity
wp-master
6.1