Medium - CVE-2024-7963 - The CMSMasters Content Composer plugin for...
The CMSMasters Content Composer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's multiple shortcodes in all versions up to, and including, 1.8.8 due to...
NA - CVE-2024-25282 - 3DSecure 2.0 allows XSS in its 3DSMethod...
3DSecure 2.0 allows XSS in its 3DSMethod Authentication via a modified params parameter in a /rest/online request with a /redirect?action=challenge&txn= substring.
NA - CVE-2024-25283 - 3DSecure 2.0 allows reflected XSS in the 3DS...
3DSecure 2.0 allows reflected XSS in the 3DS Authorization Challenge via a modified params parameter in a /rest/online request with a /redirect?action=challenge&txn= substring.
NA - CVE-2024-25285 - 3DSecure 2.0 allows form action hijacking via...
3DSecure 2.0 allows form action hijacking via threeDsMethod.jsp?threeDSMethodData= or the threeDSMethodNotificationURL parameter. The destination web site for a form submission can be modified.