Search Results (Refine Search)
- Keyword (text search): wordpress
Vuln ID | Summary | CVSS Severity |
---|---|---|
CVE-2023-2170 |
The TaxoPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Related Posts functionality in versions up to, and including, 3.6.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers with Editor+ permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. Published: April 19, 2023; 6:15:07 AM -0400 |
V3.1: 4.8 MEDIUM V2.0:(not available) |
CVE-2023-2169 |
The TaxoPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Related Posts functionality in versions up to, and including, 3.6.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers with Editor+ permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. Published: April 19, 2023; 6:15:07 AM -0400 |
V3.1: 4.8 MEDIUM V2.0:(not available) |
CVE-2023-2168 |
The TaxoPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Suggest Terms Title field in versions up to, and including, 3.6.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers with Editor+ permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. Published: April 19, 2023; 6:15:07 AM -0400 |
V3.1: 4.8 MEDIUM V2.0:(not available) |
CVE-2023-2120 |
The Thumbnail carousel slider plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the search_term parameter in versions up to, and including, 1.1.9 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link. Published: April 17, 2023; 10:15:07 PM -0400 |
V3.1: 6.1 MEDIUM V2.0:(not available) |
CVE-2023-2119 |
The Responsive Filterable Portfolio plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the search_term parameter in versions up to, and including, 1.0.19 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link. Published: April 17, 2023; 10:15:07 PM -0400 |
V3.1: 6.1 MEDIUM V2.0:(not available) |
CVE-2015-10102 |
A vulnerability, which was classified as critical, has been found in Freshdesk Plugin 1.7 on WordPress. Affected by this issue is some unknown functionality. The manipulation leads to open redirect. The attack may be launched remotely. Upgrading to version 1.8 is able to address this issue. The patch is identified as 2aaecd4e0c7c6c1dc4e6a593163d5f7aa0fa5d5b. It is recommended to upgrade the affected component. VDB-226118 is the identifier assigned to this vulnerability. Published: April 17, 2023; 2:15:07 PM -0400 |
V3.1: 6.1 MEDIUM V2.0:(not available) |
CVE-2023-1473 |
The Slider, Gallery, and Carousel by MetaSlider WordPress plugin 3.29.0 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin Published: April 17, 2023; 9:15:38 AM -0400 |
V3.1: 6.1 MEDIUM V2.0:(not available) |
CVE-2023-1427 |
- The Photo Gallery by 10Web WordPress plugin before 1.8.15 did not ensure that uploaded files are kept inside its uploads folder, allowing high privilege users to put images anywhere in the filesystem via a path traversal vector. Published: April 17, 2023; 9:15:38 AM -0400 |
V3.1: 4.9 MEDIUM V2.0:(not available) |
CVE-2023-1413 |
The WP VR WordPress plugin before 8.2.9 does not sanitise and escape some parameters before outputting them back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin Published: April 17, 2023; 9:15:38 AM -0400 |
V3.1: 6.1 MEDIUM V2.0:(not available) |
CVE-2023-1373 |
The W4 Post List WordPress plugin before 2.4.6 does not escape some URLs before outputting them in attributes, leading to Reflected Cross-Site Scripting Published: April 17, 2023; 9:15:38 AM -0400 |
V3.1: 6.1 MEDIUM V2.0:(not available) |
CVE-2023-1371 |
The W4 Post List WordPress plugin before 2.4.6 does not ensure that password protected posts can be accessed before displaying their content, which could allow any authenticated users to access them Published: April 17, 2023; 9:15:38 AM -0400 |
V3.1: 6.5 MEDIUM V2.0:(not available) |
CVE-2023-1331 |
The Redirection WordPress plugin before 1.1.5 does not have CSRF checks in the uninstall action, which could allow attackers to make logged in admins delete all the redirections through a CSRF attack. Published: April 17, 2023; 9:15:38 AM -0400 |
V3.1: 6.5 MEDIUM V2.0:(not available) |
CVE-2023-1325 |
The Easy Forms for Mailchimp WordPress plugin before 6.8.7 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks Published: April 17, 2023; 9:15:38 AM -0400 |
V3.1: 5.4 MEDIUM V2.0:(not available) |
CVE-2023-1282 |
The Drag and Drop Multiple File Upload PRO - Contact Form 7 Standard WordPress plugin before 2.11.1 and Drag and Drop Multiple File Upload PRO - Contact Form 7 with Remote Storage Integrations WordPress plugin before 5.0.6.4 do not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high-privilege users such as admins. Published: April 17, 2023; 9:15:38 AM -0400 |
V3.1: 6.1 MEDIUM V2.0:(not available) |
CVE-2023-1274 |
The Pricing Tables For WPBakery Page Builder (formerly Visual Composer) WordPress plugin before 3.0 does not validate some shortcode attributes before using them to generate paths passed to include function/s, allowing any authenticated users such as subscriber to perform LFI attacks Published: April 17, 2023; 9:15:38 AM -0400 |
V3.1: 6.5 MEDIUM V2.0:(not available) |
CVE-2023-0889 |
Themeflection Numbers WordPress plugin before 2.0.1 does not have authorisation and CSRF check in an AJAX action, and does not ensure that the options to be updated belong to the plugin. As a result, it could allow any authenticated users, such as subscriber, to update arbitrary blog options, such as enabling registration and set the default role to administrator Published: April 17, 2023; 9:15:37 AM -0400 |
V3.1: 6.5 MEDIUM V2.0:(not available) |
CVE-2023-0765 |
The Gallery by BestWebSoft WordPress plugin before 4.7.0 does not properly escape values used in SQL queries, leading to an Blind SQL Injection vulnerability. The attacker must have at least the privileges of an Author, and the vendor's Slider plugin (https://wordpress.org/plugins/slider-bws/) must also be installed for this vulnerability to be exploitable. Published: April 17, 2023; 9:15:37 AM -0400 |
V3.1: 8.8 HIGH V2.0:(not available) |
CVE-2023-0764 |
The Gallery by BestWebSoft WordPress plugin before 4.7.0 does not perform proper sanitization of gallery information, leading to a Stored Cross-Site Scription vulnerability. The attacker must have at least the privileges of the Author role. Published: April 17, 2023; 9:15:37 AM -0400 |
V3.1: 5.4 MEDIUM V2.0:(not available) |
CVE-2023-0374 |
The W4 Post List WordPress plugin before 2.4.6 does not validate and escape some of its block options before outputting them back in a page/post where the block is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks. Published: April 17, 2023; 9:15:37 AM -0400 |
V3.1: 5.4 MEDIUM V2.0:(not available) |
CVE-2023-0367 |
The Pricing Tables For WPBakery Page Builder (formerly Visual Composer) WordPress plugin before 3.0 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks Published: April 17, 2023; 9:15:37 AM -0400 |
V3.1: 5.4 MEDIUM V2.0:(not available) |