VYPR

StagTools

by Codestag

CVEs (2)

  • CVE-2023-41868HigSep 25, 2023
    risk 0.46cvss 7.1epss 0.00

    Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Ram Ratan Maurya, Codestag StagTools plugin <= 2.3.7 versions.

  • CVE-2023-0891MedMay 2, 2023
    risk 0.35cvss 5.4epss 0.00

    The StagTools WordPress plugin before 2.3.7 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting…