{"error":0,"message":null,"data":{"name":"WP Rollback &#8211; Rollback Plugins and Themes","plugin":"wp-rollback","link":"https:\/\/wordpress.org\/plugins\/wp-rollback\/","latest":"1777450560","closed":0,"closed_reason":null,"closed_date":null,"vulnerability":[{"uuid":"eb2ceb3f530a7b555c8b9131a94d6bc3ea16967dabb8d5f7fd233ffb773b0370","name":"WP Rollback &#8211; Rollback Plugins and Themes [wp-rollback] < 1.2.3","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"1.2.3","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2015-9343","name":"CVE-2015-9343","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2015-9343","description":"[en] The wp-rollback plugin before 1.2.3 for WordPress has CSRF.","date":"2019-08-27"},{"id":"dc4cd60f26750ed473696a8861043984199f34b5","name":"Rollback < 1.2.3 - Cross-Site Request Forgery","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/wp-rollback\/rollback-123-cross-site-request-forgery","description":"The wp-rollback plugin before 1.2.3 for WordPress has CSRF.","date":"2015-06-28"}],"impact":{"cvss":{"version":"3.0","vector":"CVSS:3.0\/AV:N\/AC:L\/PR:N\/UI:R\/S:U\/C:H\/I:H\/A:H","av":"n","ac":"l","pr":"n","ui":"r","s":"u","c":"h","i":"h","a":"h","score":"8.8","severity":"h","exploitable":"2.8","impact":"5.9"},"cvss3":{"version":"3.0","vector":"CVSS:3.0\/AV:N\/AC:L\/PR:N\/UI:R\/S:U\/C:H\/I:H\/A:H","score":"8.8","severity":"high","av":"network","ac":"low","pr":"none","ui":"required","s":"unchanged","c":"high","i":"high","a":"high","exploitable":"2.8","impact":"5.9"},"cwe":[{"cwe":"CWE-352","name":"Cross-Site Request Forgery (CSRF)","description":"The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor."}]}},{"uuid":"02d4448a5b8478aee54deb17dac6068b0ece6b2ee56e66233ecd622821b47f0e","name":"WP Rollback &#8211; Rollback Plugins and Themes [wp-rollback] < 1.2.3","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"1.2.3","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2015-9342","name":"CVE-2015-9342","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2015-9342","description":"[en] The wp-rollback plugin before 1.2.3 for WordPress has XSS.","date":"2019-08-27"},{"id":"0e113ee063a6ad3e88f6f831fba8eb65debe0779","name":"WP Rollback < 1.2.3 - Cross-Site Scripting","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/wp-rollback\/wp-rollback-123-cross-site-scripting","description":"The wp-rollback plugin before 1.2.3 for WordPress has Cross-Site Scripting.","date":"2015-06-28"},{"id":"ac2dee2f-ac7a-44eb-b4c8-17ae0e41ad67","name":"WP Rollback &lt;= 1.2.2 - Cross-Site Scripting (XSS) &amp; CSRF","link":"https:\/\/wpscan.com\/vulnerability\/ac2dee2f-ac7a-44eb-b4c8-17ae0e41ad67","description":"The WP Rollback WordPress plugin was affected by a Cross-Site Scripting (XSS) &amp; CSRF security vulnerability.","date":null}],"impact":{"cvss":{"version":"3.0","vector":"CVSS:3.0\/AV:N\/AC:L\/PR:N\/UI:R\/S:C\/C:L\/I:L\/A:N","av":"n","ac":"l","pr":"n","ui":"r","s":"c","c":"l","i":"l","a":"n","score":"6.1","severity":"m","exploitable":"2.8","impact":"2.7"},"cvss3":{"version":"3.0","vector":"CVSS:3.0\/AV:N\/AC:L\/PR:N\/UI:R\/S:C\/C:L\/I:L\/A:N","score":"6.1","severity":"medium","av":"network","ac":"low","pr":"none","ui":"required","s":"changed","c":"low","i":"low","a":"none","exploitable":"2.8","impact":"2.7"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}]}},{"uuid":"00ba26aca2f58300e9e60fa0bed00fb1d6a1d6c68c8d820db43050ad667ba606","name":"WP Rollback &#8211; Rollback Plugins and Themes [wp-rollback] < 1.2.3","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"1.2.3","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"a83da0fea4aa4e15938e977d7729acda943ca2c9","name":"WordPress WP Rollback Plugin <= 1.2.2 - Multiple Vulnerabilities","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/wp-rollback\/vulnerability\/wordpress-wp-rollback-plugin-1-2-2-multiple-vulnerabilities","description":"This plugin is prone to a cross site scripting and cross site request forgery vulnerabilities. Because of XSS vulnerability, the attackers can display any content with no filter from a simple URL, easy to include any remote malicious javascript file. Because of CSRF, anyone can force the installation of any plugin from the repository.\nUpdate the plugin.","date":"2015-06-28"}],"impact":[]}]},"updated":"1776153795"}