Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total3
Critical0
High0
Medium3
Reset
Showing 1-3 of 3 records
Threat Entry Updated 2024-12-18

CVE-2024-12513 - Contests By Rewards Fuel Plugin

The Contests by Rewards Fuel plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'RF_CONTEST' shortcode in all versions up to, and including, 2.0.65 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Contests By Rewards Fuel

CVE-2024-12513

MEDIUM CVSS 6.4 2024-12-18
Threat Entry Updated 2024-11-21

CVE-2024-1787 - Contests By Rewards Fuel Plugin

The Contests by Rewards Fuel plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'update_rewards_fuel_api_key' parameter in all versions up to, and including, 2.0.64 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Contests By Rewards Fuel

CVE-2024-1787

MEDIUM CVSS 6.4 2024-03-20
Threat Entry Updated 2024-11-21

CVE-2024-1785 - Contests By Rewards Fuel Plugin

The Contests by Rewards Fuel plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.0.62. This is due to missing or incorrect nonce validation on the ajax_handler() function. This makes it possible for unauthenticated attackers to update the plugin's settings and inject malicious JavaScript via a forged request granted they can trick a site's user with the edit_posts capability into performing an action such as clicking on a link.

PLUGIN Contests By Rewards Fuel

CVE-2024-1785

MEDIUM CVSS 5.4 2024-03-20
Scroll to top