Filtered by vendor Webfactoryltd Subscriptions
Filtered by product External Links In New Window \/ New Tab Subscriptions
Total 2 CVE
CVE Vendors Products Updated CVSS v3.1
CVE-2022-1583 1 Webfactoryltd 1 External Links In New Window \/ New Tab 2022-06-09 6.5 Medium
The External Links in New Window / New Tab WordPress plugin before 1.43 does not ensure window.opener is set to "null" when links to external sites are clicked, which may enable tabnabbing attacks to occur.
CVE-2022-1582 1 Webfactoryltd 1 External Links In New Window \/ New Tab 2022-06-08 6.1 Medium
The External Links in New Window / New Tab WordPress plugin before 1.43 does not properly escape URLs it concatenates to onclick event handlers, which makes Stored Cross-Site Scripting attacks possible.