Show filters
201 Total Results
Displaying 161-170 of 201
Sort by:
Attacker Value
Unknown

CVE-2023-23681

Disclosure Date: March 30, 2023 (last updated February 24, 2025)
Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Labib Ahmed Image Hover Effects For WPBakery Page Builder plugin <= 4.0 versions.
Attacker Value
Unknown

CVE-2023-0484

Disclosure Date: March 27, 2023 (last updated October 08, 2023)
The Contact Form 7 Widget For Elementor Page Builder & Gutenberg Blocks WordPress plugin before 1.1.6 does not have CSRF check when activating plugins, which could allow attackers to make logged in admins activate arbitrary plugins present on the blog via a CSRF attack
Attacker Value
Unknown

CVE-2023-22707

Disclosure Date: March 27, 2023 (last updated February 24, 2025)
Auth. (author+) Cross-Site Scripting (XSS) vulnerability in Wpsoul Greenshift – animation and page builder blocks plugin <= 4.9.9 versions.
Attacker Value
Unknown

CVE-2022-47166

Disclosure Date: March 13, 2023 (last updated February 24, 2025)
Cross-Site Request Forgery (CSRF) vulnerability in voidCoders Void Contact Form 7 Widget For Elementor Page Builder plugin <= 2.1.1 versions.
Attacker Value
Unknown

CVE-2022-48366

Disclosure Date: March 12, 2023 (last updated February 24, 2025)
An issue was discovered in eZ Platform Ibexa Kernel before 1.3.19. It allows determining account existence via a timing attack.
Attacker Value
Unknown

CVE-2023-0378

Disclosure Date: February 21, 2023 (last updated October 08, 2023)
The Greenshift WordPress plugin before 5.0 does not validate and escape some of its block options before outputting them back in a page/post where the block is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.
Attacker Value
Unknown

CVE-2022-4669

Disclosure Date: February 21, 2023 (last updated October 08, 2023)
The Page Builder: Live Composer WordPress plugin before 1.5.23 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.
Attacker Value
Unknown

CVE-2023-24382

Disclosure Date: February 14, 2023 (last updated February 24, 2025)
Cross-Site Request Forgery (CSRF) vulnerability in Photon WP Material Design Icons for Page Builders plugin <= 1.4.2 versions.
Attacker Value
Unknown

CVE-2023-0159

Disclosure Date: February 13, 2023 (last updated December 05, 2023)
The Extensive VC Addons for WPBakery page builder WordPress plugin before 1.9.1 does not validate a parameter passed to the php extract function when loading templates, allowing an unauthenticated attacker to override the template path to read arbitrary files from the hosts file system. This may be escalated to RCE using PHP filter chains.
Attacker Value
Unknown

CVE-2022-4718

Disclosure Date: January 23, 2023 (last updated October 08, 2023)
The Landing Page Builder WordPress plugin before 1.4.9.9 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as admins.