Bang tinh vay Security & Risk Analysis

wordpress.org/plugins/bang-tinh-lai-suat

Bang tinh lai vay ngan hang

40 active installs v1.0.1 PHP + WP 4.4+ Updated Sep 26, 2019
bang-tinh-vayhanhdolai-suatnqhanhtra-gop
64
C · Use Caution
CVEs total1
Unpatched1
Last CVEJun 5, 2025
Safety Verdict

Is Bang tinh vay Safe to Use in 2026?

Use With Caution

Score 64/100

Bang tinh vay has 1 unpatched vulnerability. Evaluate alternatives or apply available mitigations.

1 known CVE 1 unpatched Last CVE: Jun 5, 2025Updated 6yr ago
Risk Assessment

The "bang-tinh-lai-suat" plugin v1.0.1 exhibits a mixed security posture. On the positive side, the static analysis reveals no identified dangerous functions, no file operations, no external HTTP requests, and all SQL queries utilize prepared statements, which are strong indicators of good security practices regarding direct database interaction. The limited attack surface, with only one shortcode and no unprotected entry points found, is also a positive sign. However, a significant concern arises from the complete lack of output escaping, meaning all outputs are potentially vulnerable to Cross-Site Scripting (XSS) attacks. Furthermore, the absence of nonce checks and capability checks on the shortcode is concerning, as it could allow unauthenticated or unauthorized users to trigger its functionality.

The vulnerability history is particularly alarming. The plugin has a known CVE with a medium severity, specifically identified as Cross-Site Scripting. The fact that this vulnerability is currently unpatched is a critical red flag. The timing of the last vulnerability (2025-06-05) suggests it might be a future vulnerability or an error in the provided data, but regardless, an unpatched medium-severity XSS vulnerability poses a real risk. The recurring nature of XSS vulnerabilities, as indicated by the vulnerability history, suggests potential systemic issues in how the plugin handles user-supplied data for output, exacerbating the risk posed by the lack of output escaping in the static analysis.

Key Concerns

  • Unpatched CVE (Medium severity XSS)
  • 0% output escaping
  • No nonce checks on entry points
  • No capability checks on entry points
Vulnerabilities
1 published

Bang tinh vay Security Vulnerabilities

CVEs by Year

1 CVE in 2025 · unpatched
2025
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2023-26000medium · 4.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Bang tinh vay <= 1.0.1 - Authenticated (Administrator+) Stored Cross-Site Scripting

Jun 5, 2025Unpatched
Version History

Bang tinh vay Release Timeline

v1.0.1Current1 CVE
Code Analysis
Analyzed Mar 16, 2026

Bang tinh vay Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
2
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

0% escaped2 total outputs
Attack Surface

Bang tinh vay Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[laisuat] form.php:70
WordPress Hooks 4
actionplugins_loadedlaisuat.php:17
actionwp_enqueue_scriptslaisuat.php:28
actionadmin_initlaisuat.php:31
actionadmin_menulaisuat.php:32
Maintenance & Trust

Bang tinh vay Maintenance & Trust

Maintenance Signals

WordPress version tested5.2.24
Last updatedSep 26, 2019
PHP min version
Downloads10K

Community Trust

Rating0/100
Number of ratings0
Active installs40
Developer Profile

Bang tinh vay Developer Profile

hanhdo205

2 plugins · 100 total installs

77
trust score
Avg Security Score
75/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Bang tinh vay

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/bang-tinh-lai-suat/css/laisuat.css/wp-content/plugins/bang-tinh-lai-suat/js/laisuat.js
Script Paths
/wp-content/plugins/bang-tinh-lai-suat/js/laisuat.js
Version Parameters
bang-tinh-lai-suat/css/laisuat.css?ver=bang-tinh-lai-suat/js/laisuat.js?ver=

HTML / DOM Fingerprints

CSS Classes
input-forminput-boxshowbangtinhky-thanh-toanamount-startresult-bodytong-lai-gop+1 more
Data Attributes
data-ky-thanh-toandata-amount-startdata-goc-phai-tradata-lai-phai-tradata-tong-tien-tra
JS Globals
congthucBASE_URL
Shortcode Output
[laisuat]
FAQ

Frequently Asked Questions about Bang tinh vay