Show filters
15 Total Results
Displaying 11-15 of 15
Sort by:
Attacker Value
Unknown

CVE-2023-4269

Disclosure Date: September 04, 2023 (last updated October 08, 2023)
The User Activity Log WordPress plugin before 1.6.6 lacks proper authorisation when exporting its activity logs, allowing any authenticated users, such as subscriber to perform such action and retrieve PII such as email addresses.
Attacker Value
Unknown

CVE-2023-30485

Disclosure Date: September 04, 2023 (last updated October 08, 2023)
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Solwin Infotech Responsive WordPress Slider – Avartan Slider Lite plugin <= 1.5.3 versions.
Attacker Value
Unknown

CVE-2023-3435

Disclosure Date: August 14, 2023 (last updated October 08, 2023)
The User Activity Log WordPress plugin before 1.6.5 does not correctly sanitise and escape several parameters before using it in a SQL statement as part of its exportation feature, allowing unauthenticated attackers to conduct SQL injection attacks.
Attacker Value
Unknown

CVE-2023-2761

Disclosure Date: July 24, 2023 (last updated October 08, 2023)
The User Activity Log WordPress plugin before 1.6.3 does not properly sanitise and escape the `txtsearch` parameter before using it in a SQL statement in some admin pages, leading to a SQL injection exploitable by high privilege users such as admin.
Attacker Value
Unknown

CVE-2022-4793

Disclosure Date: January 30, 2023 (last updated February 24, 2025)
The Blog Designer WordPress plugin before 2.4.1 does not validate and escape one of its shortcode attributes, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attack.