ULeak Security & Monitoring <= 1.2.3 - Subscriber+ Stored Cross-Site Scripting
CVE-2022-1557
5.4MEDIUM
What is CVE-2022-1557?
The ULeak Security & Monitoring WordPress plugin through 1.2.3 does not have authorisation and CSRF checks when updating its settings, and is also lacking sanitisation as well as escaping in some of them, which could allow any authenticated users such as subscriber to perform Stored Cross-Site Scripting attacks against admins viewing the settings

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
ULeak Security & Monitoring Plugin 1.2.3