N/A Unfixed Closed
2023-07-18≤ 1.0.0
WordPress Nugget by Ingot: Easy, automated and native A/B testing for everyone Plugin <= 1.0.0 is vulnerable to Cross Site Scripting (XSS)
WordPress Nugget by Ingot: Easy, automated and native A/B testing for everyone Plugin <= 1.0.0 is vulnerable to Cross Site Scripting (XSS)
Freemius SDK <= 2.2.3 - Missing Authorization to Arbitrary Options Update
Freemius SDK <= 2.4.2 - Missing Authorization Checks
Freemius Library < 2.2.4 - Subscriber+ Arbitrary Option Update
WordPress "Nugget by Ingot: Easy, automated and native A/B testing for everyone" plugin <= 1.0.0 - Sensitive Information Disclosure vulnerability
WordPress "Nugget by Ingot: Easy, automated and native A/B testing for everyone" plugin <= 1.0.0 - Toggle The Debug Mode via Cross-Site Request Forgery (CSRF) vulnerability