Show filters
520 Total Results
Displaying 151-160 of 520
Sort by:
Attacker Value
Unknown

CVE-2024-32674

Disclosure Date: May 08, 2024 (last updated May 08, 2024)
Heateor Social Login WordPress prior to 1.1.32 contains a cross-site scripting vulnerability. If this vulnerability is exploited, an arbitrary script may be executed on the web browser of the user who accessed the website using the product.
0
Attacker Value
Unknown

CVE-2024-4393

Disclosure Date: May 08, 2024 (last updated January 05, 2025)
The Social Connect plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 1.2. This is due to insufficient verification on the OpenID server being supplied during the social login through the plugin. This makes it possible for unauthenticated attackers to log in as any existing user on the site, such as an administrator, if they have access to the email.
0
Attacker Value
Unknown

CVE-2024-24710

Disclosure Date: May 03, 2024 (last updated May 03, 2024)
Missing Authorization vulnerability in SlickRemix Feed Them Social.This issue affects Feed Them Social: from n/a through 4.2.0.
0
Attacker Value
Unknown

CVE-2024-1959

Disclosure Date: May 02, 2024 (last updated January 05, 2025)
The Social Sharing Plugin – Social Warfare plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'socialWarfare' shortcode in all versions up to, and including, 4.4.6.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
0
Attacker Value
Unknown

CVE-2024-33693

Disclosure Date: April 26, 2024 (last updated April 27, 2024)
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Meks Meks Smart Social Widget allows Stored XSS.This issue affects Meks Smart Social Widget: from n/a through 1.6.4.
0
Attacker Value
Unknown

CVE-2024-3678

Disclosure Date: April 26, 2024 (last updated April 26, 2024)
The Blog2Social: Social Media Auto Post & Scheduler plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 7.4.2. This makes it possible for unauthenticated attackers to view limited information from password protected posts.
0
Attacker Value
Unknown

CVE-2024-2159

Disclosure Date: April 26, 2024 (last updated April 26, 2024)
The Social Sharing Plugin WordPress plugin before 3.3.61 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks
0
Attacker Value
Unknown

CVE-2024-32879

Disclosure Date: April 24, 2024 (last updated April 25, 2024)
Python Social Auth is a social authentication/registration mechanism. Prior to version 5.4.1, due to default case-insensitive collation in MySQL or MariaDB databases, third-party authentication user IDs are not case-sensitive and could cause different IDs to match. This issue has been addressed by a fix released in version 5.4.1. An immediate workaround would be to change collation of the affected field.
0
Attacker Value
Unknown

CVE-2024-32689

Disclosure Date: April 18, 2024 (last updated April 18, 2024)
Missing Authorization vulnerability in GenialSouls WP Social Comments.This issue affects WP Social Comments: from n/a through 1.7.3.
0
Attacker Value
Unknown

CVE-2024-2118

Disclosure Date: April 17, 2024 (last updated April 17, 2024)
The Social Media Share Buttons & Social Sharing Icons WordPress plugin before 2.8.9 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)
0