VYPR

Simple Bitcoin Faucets

by WordPress

CVEs (1)

  • CVE-2022-3024Sep 26, 2022
    risk 0.00cvss epss 0.00

    The Simple Bitcoin Faucets WordPress plugin through 1.7.0 does not have any authorisation and CSRF in an AJAX action, allowing any authenticated users, such as subscribers to call it and add/delete/edit Bonds. Furthermore, due to the lack of sanitisation and escaping, it could…