{"error":0,"message":null,"data":{"name":"Add LinkedIn Insight Tag for LinkedIn Ads","plugin":"lktags-linkedin-insight-tags","link":"https:\/\/wordpress.org\/plugins\/lktags-linkedin-insight-tags\/","latest":"1789836960","closed":0,"closed_reason":null,"closed_date":null,"vulnerability":[{"uuid":"df77bdc45aceecc243dd15bc5dd89bb76b9f5fb230b7d578cbd4deb7e6bd806d","name":"Add LinkedIn Insight Tag for LinkedIn Ads [lktags-linkedin-insight-tags] < 1.2.4","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"1.2.4","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"dadda5fbc6f9cdad6d9e7c5ccd7ebafb799faf77","name":"WordPress Add Linkedin insight tags for Linkedin ads plugin <= 1.2.3 - Toggle The Debug Mode via Cross-Site Request Forgery (CSRF) vulnerability","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/lktags-linkedin-insight-tags\/vulnerability\/wordpress-add-linkedin-insight-tags-for-linkedin-ads-plugin-123-toggle-the-debug-mode-via-cross-site-request-forgery-csrf-vulnerability","description":"Toggle The Debug Mode via Cross-Site Request Forgery (CSRF) vulnerability discovered in WordPress Add Linkedin insight tags for Linkedin ads plugin (versions <= 1.2.3).","date":"2022-02-28"}],"impact":[]},{"uuid":"ef5595053f3ac30371798999f21d25c4c140f6b63217a06e1b594add7e8b582d","name":"Add LinkedIn Insight Tag for LinkedIn Ads [lktags-linkedin-insight-tags] < 1.2.4","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"1.2.4","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"8f1555fcc065784617e647a6687f7dc7c7078b53","name":"WordPress Add Linkedin insight tags for Linkedin ads plugin <= 1.2.3 - Sensitive Information Disclosure vulnerability","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/lktags-linkedin-insight-tags\/vulnerability\/wordpress-add-linkedin-insight-tags-for-linkedin-ads-plugin-123-sensitive-information-disclosure-vulnerability","description":"Sensitive Information Disclosure vulnerability discovered in WordPress Add Linkedin insight tags for Linkedin ads plugin (versions <= 1.2.3).","date":"2022-02-28"}],"impact":[]},{"uuid":"eb8f0f6f3bfcb3f33be48c0ec6db229be34ae196e96318c404ef97141d24d1b8","name":"Add LinkedIn Insight Tag for LinkedIn Ads [lktags-linkedin-insight-tags] < 1.2.4","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"1.2.4","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"6d8910c719b2a132ec93828cd37e418b19cac960","name":"Freemius SDK <= 2.4.2 - Missing Authorization Checks","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/detail\/freemius-sdk-242-missing-authorization-checks","description":"The Freemius SDK, as used by hundreds of WordPress plugin and theme developers, was vulnerable to Cross-Site Request Forgery and Information disclosure due to missing capability checks and nonce protection on the _get_debug_log, _get_db_option, and the _set_db_option functions in versions up to, and including 2.4.2. Any WordPress plugin or theme running a version of Freemius less than 2.4.3 is vulnerable.","date":"2022-03-04"},{"id":"CVE-2022-4974","name":"Freemius SDK <= 2.4.2 - Missing Authorization Checks","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2022-4974","description":"The Freemius SDK, as used by hundreds of WordPress plugin and theme developers, was vulnerable to Cross-Site Request Forgery and Information disclosure due to missing capability checks and nonce protection on the _get_debug_log, _get_db_option, and the _set_db_option functions in versions up to, and including 2.4.2. Any WordPress plugin or theme running a version of Freemius less than 2.4.3 is vulnerable.","date":"2024-10-16"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:U\/C:L\/I:L\/A:L","av":"n","ac":"l","pr":"l","ui":"n","s":"u","c":"l","i":"l","a":"l","score":"6.3","severity":"m","exploitable":"2.8","impact":"3.4"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:U\/C:L\/I:L\/A:L","score":"6.3","severity":"medium","av":"network","ac":"low","pr":"low","ui":"none","s":"unchanged","c":"low","i":"low","a":"low","exploitable":"2.8","impact":"3.4"},"cwe":[{"cwe":"CWE-862","name":"Missing Authorization","description":"The product does not perform an authorization check when an actor attempts to access a resource or perform an action."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"890df39e9dfcf807e8eecbf16c69f198daaf2110c2fff480c8c98cc27a67cca5","name":"Add LinkedIn Insight Tag for LinkedIn Ads [lktags-linkedin-insight-tags] < 1.2.6","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"1.2.6","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2023-33999","name":"CVE-2023-33999","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2023-33999","description":"[en] Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in WPVibes WP Mail Log allows DOM-Based XSS.\n\nThis issue affects WP Mail Log: from n\/a through 1.0.2.","date":"2026-06-11"},{"id":"87b098bd59685bd11809196fd8c6a981d357dc59","name":"WordPress  Add Linkedin insight tags for Linkedin ads Plugin  < 1.2.6 is vulnerable to Cross Site Scripting (XSS)","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/lktags-linkedin-insight-tags\/vulnerability\/wordpress-add-linkedin-insight-tags-for-linkedin-ads-plugin-1-2-6-reflected-cross-site-scripting-xss-vulnerability","description":"Update the plugin to the latest version.\nRafie Muhammad (Patchstack) discovered and reported this Cross Site Scripting (XSS) vulnerability in WordPress Add Linkedin insight tags for Linkedin ads Plugin. This could allow a malicious actor to inject malicious scripts, such as redirects, advertisements, and other HTML payloads into your website which will be executed when guests visit your site.  This vulnerability has been fixed in version 1.2.6.","date":"2023-07-18"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:R\/S:C\/C:L\/I:L\/A:L","av":"n","ac":"l","pr":"n","ui":"r","s":"c","c":"l","i":"l","a":"l","score":"7.1","severity":"h","exploitable":"0.0","impact":"0.0"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:R\/S:C\/C:L\/I:L\/A:L","score":"7.1","severity":"high","av":"network","ac":"low","pr":"none","ui":"required","s":"changed","c":"low","i":"low","a":"low","exploitable":"0.0","impact":"0.0"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}}]},"updated":"1774927348"}