VYPR

WP Customer Reviews

by WordPress

CVEs (2)

  • CVE-2023-4648MedOct 20, 2023
    risk 0.22cvss 4.4epss 0.00

    The WP Customer Reviews plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versions up to, and including, 3.6.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with…

  • CVE-2023-4686MedNov 22, 2023
    risk 0.21cvss 4.3epss 0.01

    The WP Customer Reviews plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 3.6.6 via the ajax_enabled_posts function. This can allow authenticated attackers to extract sensitive data such as post titles and slugs, including…