Show filters
17 Total Results
Displaying 11-17 of 17
Sort by:
Attacker Value
Unknown

CVE-2023-23646

Disclosure Date: July 17, 2023 (last updated October 08, 2023)
Cross-Site Request Forgery (CSRF) vulnerability in A WP Life Album Gallery – WordPress Gallery plugin <= 1.4.9 versions.
Attacker Value
Unknown

CVE-2022-3720

Disclosure Date: November 21, 2022 (last updated November 08, 2023)
The Event Monster WordPress plugin before 1.2.0 does not validate and escape some parameters before using them in SQL statements, which could lead to SQL Injection exploitable by high privilege users
Attacker Value
Unknown

CVE-2022-3336

Disclosure Date: November 21, 2022 (last updated November 08, 2023)
The Event Monster WordPress plugin before 1.2.0 does not have CSRF check when deleting visitors, which could allow attackers to make logged in admin delete arbitrary visitors via a CSRF attack
Attacker Value
Unknown

CVE-2021-24709

Disclosure Date: October 11, 2021 (last updated February 23, 2025)
The Weather Effect WordPress plugin before 1.3.6 does not properly validate and escape some of its settings (like *_size_leaf, *_flakes_leaf, *_speed) which could lead to Stored Cross-Site Scripting issues
Attacker Value
Unknown

CVE-2021-24683

Disclosure Date: October 11, 2021 (last updated February 23, 2025)
The Weather Effect WordPress plugin before 1.3.4 does not have any CSRF checks in place when saving its settings, and do not validate or escape them, which could lead to Stored Cross-Site Scripting issue.
Attacker Value
Unknown

CVE-2021-24529

Disclosure Date: August 23, 2021 (last updated February 23, 2025)
The Grid Gallery – Photo Image Grid Gallery WordPress plugin before 1.2.5 does not properly sanitize the title field for image galleries when adding them via the admin dashboard, resulting in an authenticated Stored Cross-Site Scripting vulnerability.
Attacker Value
Unknown

CVE-2019-17072

Disclosure Date: October 10, 2019 (last updated November 27, 2024)
The new-contact-form-widget (aka Contact Form Widget - Contact Query, Form Maker) plugin 1.0.9 for WordPress has SQL Injection via all-query-page.php.