← WordPress Vulnerabilities
WordPress security by component

Whizz

Whizz is a WordPress component with 2 published CVE records in this archive. The latest tracked vulnerability was published Apr 24, 2017; the highest CVE/CNA score is 8.1.

Plugin slug: whizz

CVE-2017-8099: Whizz: Cross-site request forgery

Whizz is affected by cross-site request forgery. Exposure depends on how the affected operation is made reachable by the site. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.

PublishedApr 24, 2017
Safe version guidanceSee mitigation notes
Safe version
Apr 24, 2017 CVE-2017-8099
Whizz: Cross-site request forgery
Whizz is affected by cross-site request forgery. Exposure depends on how the affected operation is made reachable by the site. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
See mitigation notes
CVE8.1
NVD8.1
Oct 10, 2016 CVE-2016-1000154
Whizz: Cross-site scripting
Whizz is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.1
NVD6.1