Show filters
461 Total Results
Displaying 191-200 of 461
Sort by:
Attacker Value
Unknown
CVE-2023-3292
Disclosure Date: July 31, 2023 (last updated October 08, 2023)
The grid-kit-premium WordPress plugin before 2.2.0 does not escape some parameters as well as generated URLs before outputting them in attributes, leading to Reflected Cross-Site Scripting which could be used against high privilege users such as admin
0
Attacker Value
Unknown
CVE-2023-3714
Disclosure Date: July 18, 2023 (last updated October 08, 2023)
The ProfileGrid plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'edit_group' handler in versions up to, and including, 5.5.2. This makes it possible for authenticated attackers, with group ownership, to update group options, including the 'associate_role' parameter, which defines the member's role. This issue was partially patched in version 5.5.2 preventing privilege escalation, however, it was fully patched in 5.5.3.
0
Attacker Value
Unknown
CVE-2023-3713
Disclosure Date: July 18, 2023 (last updated November 09, 2023)
The ProfileGrid plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'profile_magic_check_smtp_connection' function in versions up to, and including, 5.5.1. This makes it possible for authenticated attackers, with subscriber-level permissions or above to update the site options arbitrarily. This can be used by attackers to achieve privilege escalation.
0
Attacker Value
Unknown
CVE-2023-3403
Disclosure Date: July 18, 2023 (last updated October 08, 2023)
The ProfileGrid plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'pm_upload_csv' function in versions up to, and including, 5.5.1. This makes it possible for authenticated attackers, with subscriber-level permissions or above to import new users and update existing users.
0
Attacker Value
Unknown
CVE-2021-4423
Disclosure Date: July 12, 2023 (last updated November 09, 2023)
The RAYS Grid plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.2.2. This is due to missing or incorrect nonce validation on the rsgd_insert_update() function. This makes it possible for unauthenticated attackers to update post fields via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
0
Attacker Value
Unknown
CVE-2020-23452
Disclosure Date: July 05, 2023 (last updated October 08, 2023)
A cross-site scripting (XSS) vulnerability in Selenium Grid v3.141.59 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the hub parameter under the /grid/console page.
0
Attacker Value
Unknown
CVE-2022-46853
Disclosure Date: May 23, 2023 (last updated October 08, 2023)
Cross-Site Request Forgery (CSRF) vulnerability in RadiusTheme The Post Grid plugin <= 5.0.4 versions.
0
Attacker Value
Unknown
CVE-2023-0940
Disclosure Date: March 20, 2023 (last updated February 24, 2025)
The ProfileGrid WordPress plugin before 5.3.1 provides an AJAX endpoint for resetting a user password but does not implement proper authorization. This allows a user with low privileges, such as subscriber, to change the password of any account, including Administrator ones.
0
Attacker Value
Unknown
CVE-2022-38734
Disclosure Date: March 02, 2023 (last updated October 08, 2023)
StorageGRID (formerly StorageGRID Webscale) versions prior to 11.6.0.8 are susceptible to a Denial of Service (DoS) vulnerability. A successful exploit could lead to to a crash of the Local Distribution Router (LDR) service.
0
Attacker Value
Unknown
CVE-2023-0060
Disclosure Date: February 13, 2023 (last updated October 08, 2023)
The Responsive Gallery Grid WordPress plugin before 2.3.9 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.
0