The KKProgressbar2 Free WordPress plugin through 1.1.4.2 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack
Metrics
Affected Vendors & Products
References
History
Mon, 19 May 2025 18:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Krzysztof-furtak
Krzysztof-furtak kkprogressbar2 |
|
| Weaknesses | CWE-352 | |
| CPEs | cpe:2.3:a:krzysztof-furtak:kkprogressbar2:1.0.1:*:*:*:free:wordpress:*:* cpe:2.3:a:krzysztof-furtak:kkprogressbar2:1.0:*:*:*:free:wordpress:*:* cpe:2.3:a:krzysztof-furtak:kkprogressbar2:1.1.1:*:*:*:free:wordpress:*:* cpe:2.3:a:krzysztof-furtak:kkprogressbar2:1.1.2:*:*:*:free:wordpress:*:* cpe:2.3:a:krzysztof-furtak:kkprogressbar2:1.1.4.2:*:*:*:free:wordpress:*:* cpe:2.3:a:krzysztof-furtak:kkprogressbar2:1.1.4:*:*:*:free:wordpress:*:* cpe:2.3:a:krzysztof-furtak:kkprogressbar2:1.1:*:*:*:free:wordpress:*:* cpe:2.3:a:krzysztof-furtak:kkprogressbar2:1.2:*:*:*:free:wordpress:*:* cpe:2.3:a:krzysztof-furtak:kkprogressbar2:1.3.1:*:*:*:free:wordpress:*:* cpe:2.3:a:krzysztof-furtak:kkprogressbar2:1.3.2:*:*:*:free:wordpress:*:* cpe:2.3:a:krzysztof-furtak:kkprogressbar2:1.3:*:*:*:free:wordpress:*:* |
|
| Vendors & Products |
Krzysztof-furtak
Krzysztof-furtak kkprogressbar2 |
Fri, 09 Aug 2024 20:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: WPScan
Published: 2024-05-27T06:00:02.758Z
Updated: 2024-08-09T18:59:11.672Z
Reserved: 2024-05-05T23:28:59.278Z
Link: CVE-2024-4534
Updated: 2024-08-01T20:40:47.496Z
Status : Analyzed
Published: 2024-05-27T06:15:10.423
Modified: 2025-05-19T18:29:50.263
Link: CVE-2024-4534
No data.