Show filters
68 Total Results
Displaying 21-30 of 68
Sort by:
Attacker Value
Unknown

CVE-2024-3897

Disclosure Date: May 02, 2024 (last updated January 05, 2025)
The Popup Box – Best WordPress Popup Plugin plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the ays_pb_create_author AJAX action in all versions up to, and including, 4.3.6. This makes it possible for unauthenticated attackers to enumerate all emails registered on the website.
0
Attacker Value
Unknown

CVE-2024-3601

Disclosure Date: May 02, 2024 (last updated January 05, 2025)
The Poll Maker – Best WordPress Poll Plugin plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the ays_poll_create_author function in all versions up to, and including, 5.1.8. This makes it possible for unauthenticated attackers to extract email addresses by enumerating them one character at a time.
0
Attacker Value
Unknown

CVE-2024-3600

Disclosure Date: April 19, 2024 (last updated April 19, 2024)
The Poll Maker – Best WordPress Poll Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting due to a missing capability check on the ays_poll_maker_quick_start AJAX action in addition to insufficient escaping and sanitization in all versions up to, and including, 5.1.8. This makes it possible for unauthenticated attackers to create quizzes and inject malicious web scripts into them that execute when a user visits the page.
0
Attacker Value
Unknown

CVE-2023-35764

Disclosure Date: April 03, 2024 (last updated April 03, 2024)
Insufficient verification of data authenticity issue in Survey Maker prior to 3.6.4 allows a remote unauthenticated attacker to spoof an IP address when posting.
0
Attacker Value
Unknown

CVE-2023-34423

Disclosure Date: April 03, 2024 (last updated April 03, 2024)
Survey Maker prior to 3.6.4 contains a stored cross-site scripting vulnerability. If this vulnerability is exploited, an arbitrary script may be executed on the web browser of the user who is logging in to the website using the product with the administrative privilege.
0
Attacker Value
Unknown

CVE-2023-6591

Disclosure Date: February 12, 2024 (last updated October 10, 2024)
The Popup Box WordPress plugin before 20.9.0 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed
Attacker Value
Unknown

CVE-2023-47526

Disclosure Date: February 12, 2024 (last updated February 17, 2024)
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Chart Builder Team Chartify – WordPress Chart Plugin allows Stored XSS.This issue affects Chartify – WordPress Chart Plugin: from n/a through 2.0.6.
Attacker Value
Unknown

CVE-2024-1079

Disclosure Date: February 07, 2024 (last updated February 15, 2024)
The Quiz Maker plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the ays_show_results() function in all versions up to, and including, 6.5.2.4. This makes it possible for unauthenticated attackers to fetch arbitrary quiz results which can contain PII.
Attacker Value
Unknown

CVE-2024-1078

Disclosure Date: February 07, 2024 (last updated February 15, 2024)
The Quiz Maker plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the ays_quick_start() and add_question_rows() functions in all versions up to, and including, 6.5.2.4. This makes it possible for authenticated attackers, with subscriber-level access and above, to create arbitrary quizzes.
Attacker Value
Unknown

CVE-2024-22027

Disclosure Date: January 12, 2024 (last updated January 19, 2024)
Improper input validation vulnerability in WordPress Quiz Maker Plugin prior to 6.5.0.6 allows a remote authenticated attacker to perform a Denial of Service (DoS) attack against external services.