Show filters
64 Total Results
Displaying 21-30 of 64
Sort by:
Attacker Value
Unknown

CVE-2023-49760

Disclosure Date: December 18, 2023 (last updated December 21, 2023)
Cross-Site Request Forgery (CSRF) vulnerability in Giannopoulos Kostas WPsoonOnlinePage.This issue affects WPsoonOnlinePage: from n/a through 1.9.
Attacker Value
Unknown

CVE-2023-31275

Disclosure Date: November 27, 2023 (last updated December 01, 2023)
An uninitialized pointer use vulnerability exists in the functionality of WPS Office 11.2.0.11537 that handles Data elements in an Excel file. A specially crafted malformed file can lead to remote code execution. An attacker can provide a malicious file to trigger this vulnerability.
Attacker Value
Unknown

CVE-2023-27458

Disclosure Date: November 22, 2023 (last updated December 01, 2023)
Cross-Site Request Forgery (CSRF) vulnerability in wpstream WpStream plugin <= 4.4.10 versions.
Attacker Value
Unknown

CVE-2023-4776

Disclosure Date: October 16, 2023 (last updated October 20, 2023)
The School Management System WordPress plugin before 2.2.5 uses the WordPress esc_sql() function on a field not delimited by quotes and did not first prepare the query, leading to a SQL injection exploitable by relatively low-privilege users like Teachers.
Attacker Value
Unknown

CVE-2023-39919

Disclosure Date: September 04, 2023 (last updated October 08, 2023)
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in maennchen1.De wpShopGermany – Protected Shops plugin <= 2.0 versions.
Attacker Value
Unknown

CVE-2023-38512

Disclosure Date: July 27, 2023 (last updated October 08, 2023)
Cross-Site Request Forgery (CSRF) vulnerability in Wpstream WpStream – Live Streaming, Video on Demand, Pay Per View plugin <= 4.5.4 versions.
Attacker Value
Unknown

CVE-2023-37993

Disclosure Date: July 27, 2023 (last updated October 08, 2023)
Auth. Stored Cross-Site Scripting (XSS) vulnerability in maennchen1.De wpShopGermany IT-RECHT KANZLEI plugin <= 1.7 versions.
Attacker Value
Unknown

CVE-2023-32548

Disclosure Date: June 13, 2023 (last updated October 08, 2023)
OS command injection vulnerability exists in WPS Office version 10.8.0.6186. If a remote attacker who can conduct a man-in-the-middle attack connects the product to a malicious server and sends a specially crafted data, an arbitrary OS command may be executed on the system where the product is installed.
Attacker Value
Unknown

CVE-2020-36710

Disclosure Date: June 07, 2023 (last updated October 08, 2023)
The WPS Hide Login plugin for WordPress is vulnerable to login page disclosure even when the settings of the plugin are set to hide the login page making it possible for unauthenticated attackers to brute force credentials on sites in versions up to, and including, 1.5.4.2.
Attacker Value
Unknown

CVE-2022-2658

Disclosure Date: January 16, 2023 (last updated October 08, 2023)
The WP Spell Check WordPress plugin before 9.13 does not escape ignored words, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)