cve,link,title,description,vendor,products,score,severity,epss,cisa,cisa_published,article,ransomware,exploited,poc,trended,trended_no_1,published,trended_score CVE-2024-7420,https://securityvulnerability.io/vulnerability/CVE-2024-7420,Plugin Vulnerable to Cross-Site Request Forgery,"The Insert PHP Code Snippet plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.3.6. This is due to missing or incorrect nonce validation in the /admin/snippets.php file. This makes it possible for unauthenticated attackers to activate/deactivate and delete code snippets via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.",Wordpress,Insert PHP Code Snippet,6.5,MEDIUM,0.000539999979082495,false,,false,false,false,,false,false,2024-08-15T02:30:35.992Z,0 CVE-2024-0658,https://securityvulnerability.io/vulnerability/CVE-2024-0658,Stored Cross-Site Scripting Vulnerability in Insert PHP Code Snippet Plugin,"The Insert PHP Code Snippet plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the user's name when accessing the insert-php-code-snippet-manage page in all versions up to, and including, 1.3.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level access, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.",Wordpress,Insert PHP Code Snippet,4.4,MEDIUM,0.0004299999854993075,false,,false,false,false,,false,false,2024-02-29T01:43:00.000Z,0