Filtered by vendor Dplugins Subscriptions
Filtered by product Scripts Organizer Subscriptions
Total 1 CVE
CVE Vendors Products Updated CVSS v3.1
CVE-2021-24890 1 Dplugins 1 Scripts Organizer 2024-11-21 8.8 High
The Scripts Organizer WordPress plugin before 3.0 does not have capability and CSRF checks in the saveScript AJAX action, available to both unauthenticated and authenticated users, and does not validate user input in any way, which could allow unauthenticated users to put arbitrary PHP code in a file