Vulnerabilities (CVE)

Filtered by vendor Storeapps Subscribe
Filtered by product Temporary Login Without Password
Total 1 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2021-24836 1 Storeapps 1 Temporary Login Without Password 2024-02-04 4.0 MEDIUM 4.3 MEDIUM
The Temporary Login Without Password WordPress plugin before 1.7.1 does not have authorisation and CSRF checks when updating its settings, which could allows any logged-in users, such as subscribers to update them