Indianic Testimonial Plugin vulnerabilities
2 known vulnerabilities affecting indianic/testimonial_plugin.
Total CVEs
2
CISA KEV
0
Public exploits
2
Exploited in wild
0
Severity breakdown
HIGH1MEDIUM1
Vulnerabilities
Page 1 of 1
CVE-2013-5673P3HIGHCVSS 7.5PoCv2.22013-09-10
CVE-2013-5673 [HIGH] CWE-89 CVE-2013-5673: SQL injection vulnerability in testimonial.php in the IndiaNIC Testimonial plugin 2.2 for WordPress
SQL injection vulnerability in testimonial.php in the IndiaNIC Testimonial plugin 2.2 for WordPress allows remote attackers to execute arbitrary SQL commands via the custom_query parameter in a testimonial_add action to wp-admin/admin-ajax.php.
nvd
CVE-2013-5672P3MEDIUMCVSS 6.8PoCv2.22013-09-10
CVE-2013-5672 [MEDIUM] CWE-352 CVE-2013-5672: Multiple cross-site request forgery (CSRF) vulnerabilities in the IndiaNIC Testimonial plugin 2.2 fo
Multiple cross-site request forgery (CSRF) vulnerabilities in the IndiaNIC Testimonial plugin 2.2 for WordPress allow remote attackers to hijack the authentication of administrators for requests that (1) add a testimonial via an iNIC_testimonial_save action; (2) add a listing template via an iNIC_testimonial_save_listing_template action; (3) add a wid
nvd