Show filters
56 Total Results
Displaying 11-20 of 56
Sort by:
Attacker Value
Unknown

CVE-2024-0659

Disclosure Date: February 05, 2024 (last updated February 08, 2025)
The Easy Digital Downloads – Sell Digital Files (eCommerce Store & Payments Made Easy) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the variable pricing option title in all versions up to, and including, 3.2.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with shop manger-level access, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Attacker Value
Unknown

CVE-2023-51684

Disclosure Date: February 01, 2024 (last updated February 08, 2025)
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Easy Digital Downloads Easy Digital Downloads – Sell Digital Files (eCommerce Store & Payments Made Easy) allows Stored XSS.This issue affects Easy Digital Downloads – Sell Digital Files (eCommerce Store & Payments Made Easy): from n/a through 3.2.5.
Attacker Value
Unknown

CVE-2023-6114

Disclosure Date: December 26, 2023 (last updated January 06, 2024)
The Duplicator WordPress plugin before 1.5.7.1, Duplicator Pro WordPress plugin before 4.5.14.2 does not disallow listing the `backups-dup-lite/tmp` directory (or the `backups-dup-pro/tmp` directory in the Pro version), which temporarily stores files containing sensitive data. When directory listing is enabled in the web server, this allows unauthenticated attackers to discover and access these sensitive files, which include a full database dump and a zip archive of the site.
Attacker Value
Unknown

CVE-2023-3081

Disclosure Date: July 12, 2023 (last updated October 08, 2023)
The WP Mail Logging plugin for WordPress is vulnerable to Stored Cross-Site Scripting via email contents in versions up to, and including, 1.11.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. Note: An incomplete fix was released in 1.11.1.
Attacker Value
Unknown

CVE-2023-33309

Disclosure Date: May 28, 2023 (last updated October 08, 2023)
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Awesome Motive Duplicator Pro plugin <= 4.5.11 versions.
Attacker Value
Unknown

CVE-2023-30869

Disclosure Date: May 02, 2023 (last updated February 08, 2025)
Improper Authentication vulnerability in Easy Digital Downloads plugin allows unauth. Privilege Escalation. This issue affects Easy Digital Downloads: from 3.1 through 3.1.1.4.1.
Attacker Value
Unknown

CVE-2022-3600

Disclosure Date: November 21, 2022 (last updated February 08, 2025)
The Easy Digital Downloads WordPress plugin before 3.1.0.2 does not validate data when its output in a CSV file, which could lead to CSV injection.
Attacker Value
Unknown

CVE-2022-2387

Disclosure Date: November 07, 2022 (last updated February 08, 2025)
The Easy Digital Downloads WordPress plugin before 3.0 does not have CSRF check in place when deleting payment history, and does not ensure that the post to be deleted is actually a payment history. As a result, attackers could make a logged in admin delete arbitrary post via a CSRF attack
Attacker Value
Unknown

CVE-2022-33900

Disclosure Date: August 10, 2022 (last updated February 08, 2025)
PHP Object Injection vulnerability in Easy Digital Downloads plugin <= 3.0.1 at WordPress.
Attacker Value
Unknown

CVE-2022-0707

Disclosure Date: April 18, 2022 (last updated February 08, 2025)
The Easy Digital Downloads WordPress plugin before 2.11.6 does not have CSRF check in place when inserting payment notes, which could allow attackers to make a logged admin insert arbitrary notes via a CSRF attack