Show filters
20 Total Results
Displaying 11-20 of 20
Sort by:
Attacker Value
Unknown
CVE-2023-3169
Disclosure Date: September 11, 2023 (last updated October 08, 2023)
The tagDiv Composer WordPress plugin before 4.2, used as a companion by the Newspaper and Newsmag themes from tagDiv, does not have authorisation in a REST route and does not validate as well as escape some parameters when outputting them back, which could allow unauthenticated users to perform Stored Cross-Site Scripting attacks.
0
Attacker Value
Unknown
CVE-2023-1597
Disclosure Date: July 10, 2023 (last updated October 08, 2023)
The tagDiv Cloud Library WordPress plugin before 2.7 does not have authorisation and CSRF in an AJAX action accessible to both unauthenticated and authenticated users, allowing unauthenticated users to change arbitrary user metadata, which could lead to privilege escalation by setting themselves as an admin of the blog.
0
Attacker Value
Unknown
CVE-2023-1596
Disclosure Date: May 15, 2023 (last updated October 08, 2023)
The tagDiv Composer WordPress plugin before 4.0 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin
0
Attacker Value
Unknown
CVE-2022-3477
Disclosure Date: November 14, 2022 (last updated December 22, 2024)
The tagDiv Composer WordPress plugin before 3.5, required by the Newspaper WordPress theme before 12.1 and Newsmag WordPress theme before 5.2.2, does not properly implement the Facebook login feature, allowing unauthenticated attackers to login as any user by just knowing their email address
0
Attacker Value
Unknown
CVE-2022-2627
Disclosure Date: October 31, 2022 (last updated December 22, 2024)
The Newspaper WordPress theme before 12 does not sanitise a parameter before outputting it back in an HTML attribute via an AJAX action, leading to a Reflected Cross-Site Scripting.
0
Attacker Value
Unknown
CVE-2022-2167
Disclosure Date: October 31, 2022 (last updated December 22, 2024)
The Newspaper WordPress theme before 12 does not sanitise a parameter before outputting it back in an HTML attribute via an AJAX action, leading to a Reflected Cross-Site Scripting
0
Attacker Value
Unknown
CVE-2021-24304
Disclosure Date: August 09, 2021 (last updated February 23, 2025)
The Newsmag WordPress theme before 5.0 does not sanitise the td_block_id parameter in its td_ajax_block AJAX action, leading to an unauthenticated Reflected Cross-site Scripting (XSS) vulnerability.
0
Attacker Value
Unknown
CVE-2021-3135
Disclosure Date: July 19, 2021 (last updated February 23, 2025)
An issue was discovered in the tagDiv Newspaper theme 10.3.9.1 for WordPress. It allows XSS via the wp-admin/admin-ajax.php td_block_id parameter in a td_ajax_block API call.
0
Attacker Value
Unknown
CVE-2016-10972
Disclosure Date: September 16, 2019 (last updated November 27, 2024)
The newspaper theme before 6.7.2 for WordPress has a lack of options access control via td_ajax_update_panel.
0
Attacker Value
Unknown
CVE-2017-18634
Disclosure Date: September 16, 2019 (last updated November 27, 2024)
The newspaper theme before 6.7.2 for WordPress has script injection via td_ads[header] to admin-ajax.php.
0