The KKProgressbar2 Free WordPress plugin through 1.1.4.2 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack
Metrics
Affected Vendors & Products
References
History
Mon, 19 May 2025 18:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Krzysztof-furtak
Krzysztof-furtak kkprogressbar2 |
|
Weaknesses | CWE-352 | |
CPEs | cpe:2.3:a:krzysztof-furtak:kkprogressbar2:1.0.1:*:*:*:free:wordpress:*:* cpe:2.3:a:krzysztof-furtak:kkprogressbar2:1.0:*:*:*:free:wordpress:*:* cpe:2.3:a:krzysztof-furtak:kkprogressbar2:1.1.1:*:*:*:free:wordpress:*:* cpe:2.3:a:krzysztof-furtak:kkprogressbar2:1.1.2:*:*:*:free:wordpress:*:* cpe:2.3:a:krzysztof-furtak:kkprogressbar2:1.1.4.2:*:*:*:free:wordpress:*:* cpe:2.3:a:krzysztof-furtak:kkprogressbar2:1.1.4:*:*:*:free:wordpress:*:* cpe:2.3:a:krzysztof-furtak:kkprogressbar2:1.1:*:*:*:free:wordpress:*:* cpe:2.3:a:krzysztof-furtak:kkprogressbar2:1.2:*:*:*:free:wordpress:*:* cpe:2.3:a:krzysztof-furtak:kkprogressbar2:1.3.1:*:*:*:free:wordpress:*:* cpe:2.3:a:krzysztof-furtak:kkprogressbar2:1.3.2:*:*:*:free:wordpress:*:* cpe:2.3:a:krzysztof-furtak:kkprogressbar2:1.3:*:*:*:free:wordpress:*:* |
|
Vendors & Products |
Krzysztof-furtak
Krzysztof-furtak kkprogressbar2 |
Fri, 09 Aug 2024 20:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: WPScan
Published:
Updated: 2024-08-09T18:59:11.672Z
Reserved: 2024-05-05T23:28:59.278Z
Link: CVE-2024-4534

Updated: 2024-08-01T20:40:47.496Z

Status : Analyzed
Published: 2024-05-27T06:15:10.423
Modified: 2025-05-19T18:29:50.263
Link: CVE-2024-4534

No data.