Aggregates CVE and security vulnerability intelligence across all onetarek-related products, including CVSS, EPSS, publication dates, and vulnerability intelligence data.
Historical issues mainly involve vendor risk csrf and vendor risk cross-site scripting and related problems; some flaws may lead to vendor impact session compromise, affecting vendor surface file processing scenarios.
| CVE | Summary | Source | Max CVSS | EPSS % | Published | Updated |
|---|---|---|---|---|---|---|
| CVE-2024-4477 | The WP Logs Book WordPress plugin through 1.0.1 does not sanitise and escape some of its log data before outputting them back in an admin dashboard, leading to an Unauthenticated Stored Cross-Site Scripting | [email protected] | 5.4 | 0.31% | 2024-06-21 | 2024-11-21 |
| CVE-2024-4475 | The WP Logs Book WordPress plugin through 1.0.1 does not have CSRF check when clearing logs, which could allow attackers to make a logged in admin clear the logs them via a CSRF attack | [email protected] | 4.3 | 0.18% | 2024-06-21 | 2024-11-21 |
| CVE-2024-4474 | The WP Logs Book WordPress plugin through 1.0.1 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack | [email protected] | 4.3 | 5.96% | 2024-06-21 | 2024-11-21 |