Vendor
Dash10
Products
1
CVEs
3
Across products
3
Status
Private
Products
1- 3 CVEs
Recent CVEs
3| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2015-9435 | Cri | 0.64 | 9.8 | 0.02 | Sep 26, 2019 | The oauth2-provider plugin before 3.1.5 for WordPress has incorrect generation of random numbers. | ||
| CVE-2022-4148 | Med | 0.28 | 4.3 | 0.00 | Mar 20, 2023 | The WP OAuth Server (OAuth Authentication) WordPress plugin before 4.3.0 has a flawed CSRF and authorisation check when deleting a client, which could allow any authenticated users, such as subscriber to delete arbitrary client. | ||
| CVE-2022-3894 | Med | 0.28 | 4.3 | 0.00 | Mar 20, 2023 | The WP OAuth Server (OAuth Authentication) WordPress plugin before 4.2.5 does not have CSRF check when deleting a client, and does not ensure that the object to be deleted is actually a client, which could allow attackers to make a logged in admin delete arbitrary client and… |
- risk 0.64cvss 9.8epss 0.02
The oauth2-provider plugin before 3.1.5 for WordPress has incorrect generation of random numbers.
- risk 0.28cvss 4.3epss 0.00
The WP OAuth Server (OAuth Authentication) WordPress plugin before 4.3.0 has a flawed CSRF and authorisation check when deleting a client, which could allow any authenticated users, such as subscriber to delete arbitrary client.
- risk 0.28cvss 4.3epss 0.00
The WP OAuth Server (OAuth Authentication) WordPress plugin before 4.2.5 does not have CSRF check when deleting a client, and does not ensure that the object to be deleted is actually a client, which could allow attackers to make a logged in admin delete arbitrary client and…