cve,link,title,description,vendor,products,score,severity,epss,cisa,cisa_published,article,ransomware,exploited,poc,trended,trended_no_1,published,trended_score CVE-2024-8965,https://securityvulnerability.io/vulnerability/CVE-2024-8965,Stored Cross-Site Scripting Vulnerability in Absolute Reviews Plugin,"The Absolute Reviews plugin for WordPress is prone to a Stored Cross-Site Scripting (XSS) vulnerability that arises in the 'Name' field of a custom post criteria. This issue stems from inadequate input sanitization and output escaping practices. As a result, authenticated attackers with Contributor-level access or higher can inject malicious web scripts. The injected scripts can be executed whenever any user accesses the compromised page, potentially leading to unauthorized actions and information theft.",Wordpress,Absolute Reviews,5.4,MEDIUM,0.00044999999227002263,false,,false,false,false,,false,false,2024-09-27T05:31:01.915Z,0 CVE-2021-4426,https://securityvulnerability.io/vulnerability/CVE-2021-4426,Cross-Site Request Forgery Vulnerability in Absolute Reviews Plugin for WordPress,"The Absolute Reviews plugin for WordPress is susceptible to a Cross-Site Request Forgery (CSRF) attack, affecting versions up to and including 1.0.8. This vulnerability arises from the absence of proper nonce validation within the metabox_review_save() function. As a result, unauthorized individuals could potentially exploit this flaw by deceiving an administrator into executing a crafted request, allowing them to save harmful meta tags without adequate permissions.",Wordpress,Absolute Reviews,4.3,MEDIUM,0.00046999999904073775,false,,false,false,false,,false,false,2023-07-12T07:21:51.006Z,0