The Simple Bitcoin Faucets WordPress plugin through 1.7.0 does not have any authorisation and CSRF in an AJAX action, allowing any authenticated users, such as subscribers to call it and add/delete/edit Bonds. Furthermore, due to the lack of sanitisation and escaping, it could also lead to Stored Cross-Site Scripting issues
References
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: WPScan

Published: 2022-09-26T00:00:00

Updated: 2022-11-07T00:00:00

Reserved: 2022-08-29T00:00:00


Link: CVE-2022-3024

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2022-09-26T13:15:10.707

Modified: 2022-12-09T19:39:19.380


Link: CVE-2022-3024

JSON object: View

cve-icon Redhat Information

No data.