Show filters
13,174 Total Results
Displaying 1,021-1,030 of 10,000
Refine your search criteria for more targeted results.
Sort by:
Attacker Value
Unknown

CVE-2022-3836

Disclosure Date: January 16, 2024 (last updated January 25, 2024)
The Seed Social WordPress plugin before 2.0.4 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).
Attacker Value
Unknown

CVE-2022-3829

Disclosure Date: January 16, 2024 (last updated January 24, 2024)
The Font Awesome 4 Menus WordPress plugin through 4.7.0 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).
Attacker Value
Unknown

CVE-2022-3764

Disclosure Date: January 16, 2024 (last updated January 24, 2024)
The plugin does not filter the "delete_entries" parameter from user requests, leading to an SQL Injection vulnerability.
Attacker Value
Unknown

CVE-2022-23179

Disclosure Date: January 16, 2024 (last updated January 24, 2024)
The Contact Form & Lead Form Elementor Builder WordPress plugin before 1.7.0 does not escape some of its form fields before outputting them in attributes, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed
Attacker Value
Unknown

CVE-2022-1538

Disclosure Date: January 16, 2024 (last updated January 20, 2024)
Theme Demo Import WordPress plugin before 1.1.1 does not validate the imported file, allowing high-privilege users such as admin to upload arbitrary files (such as PHP) even when FILE_MODS and FILE_EDIT are disallowed.
Attacker Value
Unknown

CVE-2021-25117

Disclosure Date: January 16, 2024 (last updated January 20, 2024)
The WP-PostRatings WordPress plugin before 1.86.1 does not sanitise the postratings_image parameter from its options page (wp-admin/admin.php?page=wp-postratings/postratings-options.php). Even though the page is only accessible to administrators, and protected against CSRF attacks, the issue is still exploitable when the unfiltered_html capability is disabled.
Attacker Value
Unknown

CVE-2021-24151

Disclosure Date: January 16, 2024 (last updated January 24, 2024)
The WP Editor WordPress plugin before 1.2.7 did not sanitise or validate its setting fields leading to an authenticated (admin+) blind SQL injection issue via an arbitrary parameter when making a request to save the settings.
Attacker Value
Unknown

CVE-2024-0558

Disclosure Date: January 15, 2024 (last updated January 24, 2024)
A vulnerability has been found in DedeBIZ 6.3.0 and classified as critical. This vulnerability affects unknown code of the file /admin/makehtml_freelist_action.php. The manipulation of the argument startid leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. VDB-250726 is the identifier assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
Attacker Value
Unknown

CVE-2023-6941

Disclosure Date: January 15, 2024 (last updated January 20, 2024)
The Keap Official Opt-in Forms WordPress plugin through 1.0.11 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example, in multisite setup).
Attacker Value
Unknown

CVE-2023-6620

Disclosure Date: January 15, 2024 (last updated January 20, 2024)
The POST SMTP Mailer WordPress plugin before 2.8.7 does not properly sanitise and escape several parameters before using them in SQL statements, leading to a SQL injection exploitable by high privilege users such as admin.