Show filters
42 Total Results
Displaying 11-20 of 42
Sort by:
Attacker Value
Unknown
CVE-2023-4963
Disclosure Date: September 15, 2023 (last updated October 08, 2023)
The WS Facebook Like Box Widget for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'ws-facebook-likebox' shortcode in versions up to, and including, 5.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
0
Attacker Value
Unknown
CVE-2014-125097
Disclosure Date: April 10, 2023 (last updated October 20, 2023)
A vulnerability, which was classified as problematic, was found in BestWebSoft Facebook Like Button up to 2.33. Affected is the function fcbkbttn_settings_page of the file facebook-button-plugin.php. The manipulation leads to cross site scripting. It is possible to launch the attack remotely. Upgrading to version 2.34 is able to address this issue. The patch is identified as b766da8fa100779409a953f0e46c2a2448cbe99c. It is recommended to upgrade the affected component. VDB-225354 is the identifier assigned to this vulnerability.
0
Attacker Value
Unknown
CVE-2012-10012
Disclosure Date: April 10, 2023 (last updated October 12, 2023)
A vulnerability has been found in BestWebSoft Facebook Like Button up to 2.13 and classified as problematic. Affected by this vulnerability is the function fcbk_bttn_plgn_settings_page of the file facebook-button-plugin.php. The manipulation leads to cross-site request forgery. The attack can be launched remotely. The patch is named 33144ae5a45ed07efe7fceca901d91365fdbf7cb. It is recommended to apply a patch to fix this issue. The associated identifier of this vulnerability is VDB-225355.
0
Attacker Value
Unknown
CVE-2022-0209
Disclosure Date: June 13, 2022 (last updated October 07, 2023)
The Mitsol Social Post Feed WordPress plugin before 1.11 does not escape some of its settings before outputting them back in attributes, which could allow high privilege users such as admin to perform cross-Site Scripting attacks even when the unfiltered_html capability is disallowed
0
Attacker Value
Unknown
CVE-2021-24218
Disclosure Date: April 12, 2021 (last updated February 22, 2025)
The wp_ajax_save_fbe_settings and wp_ajax_delete_fbe_settings AJAX actions of the Facebook for WordPress plugin before 3.0.4 were vulnerable to CSRF due to a lack of nonce protection. The settings in the saveFbeSettings function had no sanitization allowing for script tags to be saved.
0
Attacker Value
Unknown
CVE-2021-24217
Disclosure Date: April 12, 2021 (last updated February 22, 2025)
The run_action function of the Facebook for WordPress plugin before 3.0.0 deserializes user supplied data making it possible for PHP objects to be supplied creating an Object Injection vulnerability. There was also a useable magic method in the plugin that could be used to achieve remote code execution.
0
Attacker Value
Unknown
CVE-2013-4593
Disclosure Date: December 11, 2019 (last updated November 27, 2024)
RubyGem omniauth-facebook has an access token security vulnerability
0
Attacker Value
Unknown
CVE-2019-15841
Disclosure Date: August 30, 2019 (last updated November 27, 2024)
The facebook-for-woocommerce plugin before 1.9.15 for WordPress has CSRF via ajax_woo_infobanner_post_click, ajax_woo_infobanner_post_xout, or ajax_fb_toggle_visibility.
0
Attacker Value
Unknown
CVE-2019-15840
Disclosure Date: August 30, 2019 (last updated November 27, 2024)
The facebook-for-woocommerce plugin before 1.9.14 for WordPress has CSRF.
0
Attacker Value
Unknown
CVE-2018-0579
Disclosure Date: May 14, 2018 (last updated November 26, 2024)
Cross-site scripting vulnerability in Open Graph for Facebook, Google+ and Twitter Card Tags plugin prior to version 2.2.4.1 for WordPress allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
0