VYPR

Dynamic Widgets

by WordPress

CVEs (2)

  • CVE-2021-24933MedFeb 28, 2022
    risk 0.35cvss 5.4epss 0.01

    The Dynamic Widgets WordPress plugin through 1.5.16 does not escape the prefix parameter before outputting it back in an attribute when using the term_tree AJAX action (available to any authenticated users), leading to a Reflected Cross-Site Scripting issue

  • CVE-2024-51669MedNov 19, 2024
    risk 0.28cvss 4.3epss 0.00

    Cross-Site Request Forgery (CSRF) vulnerability in Kalmang Dynamic Widgets dynamic-widgets.This issue affects Dynamic Widgets: from n/a through <= 1.6.4.