Show filters
15 Total Results
Displaying 11-15 of 15
Sort by:
Attacker Value
Unknown
CVE-2023-4269
Disclosure Date: September 04, 2023 (last updated October 08, 2023)
The User Activity Log WordPress plugin before 1.6.6 lacks proper authorisation when exporting its activity logs, allowing any authenticated users, such as subscriber to perform such action and retrieve PII such as email addresses.
0
Attacker Value
Unknown
CVE-2023-30485
Disclosure Date: September 04, 2023 (last updated October 08, 2023)
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Solwin Infotech Responsive WordPress Slider – Avartan Slider Lite plugin <= 1.5.3 versions.
0
Attacker Value
Unknown
CVE-2023-3435
Disclosure Date: August 14, 2023 (last updated October 08, 2023)
The User Activity Log WordPress plugin before 1.6.5 does not correctly sanitise and escape several parameters before using it in a SQL statement as part of its exportation feature, allowing unauthenticated attackers to conduct SQL injection attacks.
0
Attacker Value
Unknown
CVE-2023-2761
Disclosure Date: July 24, 2023 (last updated October 08, 2023)
The User Activity Log WordPress plugin before 1.6.3 does not properly sanitise and escape the `txtsearch` parameter before using it in a SQL statement in some admin pages, leading to a SQL injection exploitable by high privilege users such as admin.
0
Attacker Value
Unknown
CVE-2022-4793
Disclosure Date: January 30, 2023 (last updated February 24, 2025)
The Blog Designer WordPress plugin before 2.4.1 does not validate and escape one of its shortcode attributes, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attack.
0