Wayne-Ker

2 exploits Active since Mar 2024
CVE-2024-7313 NOMISEC MEDIUM WORKING POC
Shield Security < 20.0.6 - Reflected Cross-Site Scripting
The Shield Security WordPress plugin before 20.0.6 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.
3 stars
CVSS 6.1
CVE-2023-6444 NOMISEC MEDIUM WORKING POC
Seriously Simple Podcasting <3.0.0 - Info Disclosure
The Seriously Simple Podcasting WordPress plugin before 3.0.0 discloses the Podcast owner's email address (which by default is the admin email address) via an unauthenticated crafted request.
CVSS 5.3