RSS   Vulnerabilities for 'Images to webp'   RSS

2021-11-23
 
CVE-2021-24641

CWE-352
 

 
The Images to WebP WordPress plugin before 1.9 does not have CSRF checks in place when performing some administrative actions, which could result in modification of plugin settings, Denial-of-Service, as well as arbitrary image conversion

 
 
CVE-2021-24644

CWE-22
 

 
The Images to WebP WordPress plugin before 1.9 does not validate or sanitise the tab parameter before passing it to the include() function, which could lead to a Local File Inclusion issue

 


Copyright 2021, cxsecurity.com

 

Back to Top