WordPress Plugin Sermon Browser Cross-Site Scripting and SQL Injection Vulnerabilities - Vulnerability Database

WordPress Plugin Sermon Browser Cross-Site Scripting and SQL Injection Vulnerabilities

Critical
Reference: No Reference
Title: WordPress Plugin Sermon Browser Cross-Site Scripting and SQL Injection Vulnerabilities
Overview:

WordPress Plugin Sermon Browser is prone to a cross-site scripting vulnerability and an SQL injection vulnerability because the application fails to sufficiently sanitize user-supplied input. Exploiting these issues could allow an attacker to steal cookie-based authentication credentials compromise the application access or modify data or exploit latent vulnerabilities in the underlying database. WordPress Plugin Sermon Browser version 0.43 is vulnerable other versions may also be affected.