Show filters
17 Total Results
Displaying 11-17 of 17
Sort by:
Attacker Value
Unknown
CVE-2023-23646
Disclosure Date: July 17, 2023 (last updated October 08, 2023)
Cross-Site Request Forgery (CSRF) vulnerability in A WP Life Album Gallery – WordPress Gallery plugin <= 1.4.9 versions.
0
Attacker Value
Unknown
CVE-2022-3720
Disclosure Date: November 21, 2022 (last updated November 08, 2023)
The Event Monster WordPress plugin before 1.2.0 does not validate and escape some parameters before using them in SQL statements, which could lead to SQL Injection exploitable by high privilege users
0
Attacker Value
Unknown
CVE-2022-3336
Disclosure Date: November 21, 2022 (last updated November 08, 2023)
The Event Monster WordPress plugin before 1.2.0 does not have CSRF check when deleting visitors, which could allow attackers to make logged in admin delete arbitrary visitors via a CSRF attack
0
Attacker Value
Unknown
CVE-2021-24709
Disclosure Date: October 11, 2021 (last updated February 23, 2025)
The Weather Effect WordPress plugin before 1.3.6 does not properly validate and escape some of its settings (like *_size_leaf, *_flakes_leaf, *_speed) which could lead to Stored Cross-Site Scripting issues
0
Attacker Value
Unknown
CVE-2021-24683
Disclosure Date: October 11, 2021 (last updated February 23, 2025)
The Weather Effect WordPress plugin before 1.3.4 does not have any CSRF checks in place when saving its settings, and do not validate or escape them, which could lead to Stored Cross-Site Scripting issue.
0
Attacker Value
Unknown
CVE-2021-24529
Disclosure Date: August 23, 2021 (last updated February 23, 2025)
The Grid Gallery – Photo Image Grid Gallery WordPress plugin before 1.2.5 does not properly sanitize the title field for image galleries when adding them via the admin dashboard, resulting in an authenticated Stored Cross-Site Scripting vulnerability.
0
Attacker Value
Unknown
CVE-2019-17072
Disclosure Date: October 10, 2019 (last updated November 27, 2024)
The new-contact-form-widget (aka Contact Form Widget - Contact Query, Form Maker) plugin 1.0.9 for WordPress has SQL Injection via all-query-page.php.
0