VYPR

Wp Vipergb

by Justin Klein

Source repositories

CVEs (2)

  • CVE-2024-4409MedMay 24, 2024
    risk 0.28cvss 4.3epss 0.00

    The WP-ViperGB plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.6.1. This is due to missing or incorrect nonce validation when saving plugin settings. This makes it possible for unauthenticated attackers to change the…

  • CVE-2014-9460Jan 2, 2015
    risk 0.00cvss epss 0.01

    Multiple cross-site request forgery (CSRF) vulnerabilities in the WP-ViperGB plugin before 1.3.11 for WordPress allow remote attackers to hijack the authentication of administrators for requests that (1) change plugin settings via unspecified vectors or conduct cross-site…