N/A Unfixed
2023-07-18≤ 1.4.8
WordPress Widgets for SiteOrigin Plugin <= 1.4.8 is vulnerable to Cross Site Scripting (XSS)
Minimum safe version
1.4.3
Update to 1.4.3 or later to address 2 fixable vulnerabilities
WordPress Widgets for SiteOrigin Plugin <= 1.4.8 is vulnerable to Cross Site Scripting (XSS)
Freemius SDK <= 2.2.3 - Missing Authorization to Arbitrary Options Update
Freemius Library < 2.2.4 - Subscriber+ Arbitrary Option Update
WordPress Widgets for SiteOrigin plugin <= 1.4.8 - Sensitive Information Disclosure vulnerability
WordPress Widgets for SiteOrigin plugin <= 1.4.8 - Toggle The Debug Mode via Cross-Site Request Forgery (CSRF) vulnerability