Igor Benic Vulnerabilities and Affected Products
Vulnerabilities associated with Simple Giveaways – Grow your business, email lists and traffic with contests.
Products
Clear product- Simple Giveaways3 vulnerabilities
- Simple Giveaways – Grow your business, email lists and traffic with contests2 vulnerabilities
- LeanPress1 vulnerability
- Pets1 vulnerability
- Recipe Maker For Your Food Blog from Zip Recipes1 vulnerability
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2023-31086MEDIUM | WordPress Simple Giveaways Plugin <= 2.46.0 is vulnerable to Cross Site Request Forgery (CSRF)Cross-Site Request Forgery (CSRF) vulnerability in Igor Benic Simple Giveaways – Grow your business, email lists and traffic with contests plugin <= 2.46.0 versions. CWE-352Nov 9, 2023 | CVSS5.4v3.1 | EPSS0.306% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2021-24298MEDIUM | Simple Giveaways < 2.36.2 - Unauthenticated Reflected Cross-Site Scripting (XSS)The method and share GET parameters of the Giveaway pages were not sanitised, validated or escaped before being output back in the pages, thus leading to reflected XSS | CVSS6.1v3.1 | EPSS3.45% | PoCs2 | SignalsNot listed in CISA KEVNo known ransomware use1 Nuclei template | STIX |