Vlad Vector

2 exploits Active since Jun 2020
CVE-2020-15363 EXPLOITDB CRITICAL WORKING POC
nexos < 1.7 - SQL Injection via search_order Parameter
The Nexos theme through 1.7 for WordPress allows side-map/?search_order= SQL Injection.
CVSS 9.8
CVE-2020-15364 EXPLOITDB MEDIUM text WORKING POC
nexos < 1.7 - Cross-Site Scripting via search_location Parameter
The Nexos theme through 1.7 for WordPress allows top-map/?search_location= reflected XSS.
CVSS 6.1