Simple Bitcoin Faucets by Alexey Trofimov <= 1.7.0 - Unauthorised AJAX request to Stored XSS
LANACOMMONVDB ID: 6094f9ae-722b-4a1a-8c5d-2da16d22700f
The plugin does not have any authorisation and Cross-Site Request Forgery (CSRF) check in an AJAX action, allowing any authenticated users, such as subscribers to call it and add/delete/edit Bonds. Furthermore, due to the lack of sanitisation and escaping, it could also lead to Stored Cross-Site Scripting (XSS) issues.