VYPR

Wplegalpages

by Wpeka

Source repositories

CVEs (2)

  • CVE-2021-25106MedFeb 7, 2022
    risk 0.35cvss 5.4epss 0.01

    The Privacy Policy Generator, Terms & Conditions Generator WordPress Plugin : WPLegalPages WordPress plugin before 2.7.1 does not check for authorisation and has a flawed CSRF logic when saving its settings, allowing any authenticated users, such as subscriber, to update them.…

  • CVE-2023-4968MedOct 20, 2023
    risk 0.29cvss 5.5epss 0.00

    The WPLegalPages plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'wplegalpage' shortcode in versions up to, and including, 2.9.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated…