Loading product vulnerabilities…
Total
2
Critical
0
High
1
Medium
0
CISA KEV
0
The Sermon Browser WordPress plugin through 0.45.22 does not have CSRF checks in place when uploading Sermon files, and does not validate them in any way, allowing attackers to make a logged in admin upload arbitrary files such as PHP ones.
The sermon-browser plugin before 0.45.16 for WordPress has multiple XSS issues.