VYPR

Security Audit

by Securemoz

CVEs (2)

  • CVE-2021-24901MedFeb 28, 2022
    risk 0.35cvss 4.8epss 0.05

    The Security Audit WordPress plugin through 1.0.0 does not sanitise and escape the Data Id setting, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.

  • CVE-2015-6828Sep 16, 2015
    risk 0.00cvss epss 0.02

    The tweet_info function in class/__functions.php in the SecureMoz Security Audit plugin 1.0.5 and earlier for WordPress does not use an HTTPS session for downloading serialized data, which allows man-in-the-middle attackers to conduct PHP object injection attacks and execute…