CVE-2015-9437, CVE-2015-9436
The Dynamic Widgets plugin prior to version 1.5.11 contains a cross-site request forgery vulnerability that can lead to stored cross-site scripting attacks through the page_limit parameter on the plugin's configuration page accessed via wp-admin/themes.php?page=dynwid-config. An attacker could exploit this flaw to perform unauthorized actions and inject malicious scripts that execute in the context of administrator sessions. Users should upgrade to version 1.5.11 or later to remediate this issue.
Based on public CVE data (MITRE/NVD).