Show filters
26 Total Results
Displaying 21-26 of 26
Sort by:
Attacker Value
Unknown
CVE-2021-24592
Disclosure Date: August 30, 2021 (last updated February 23, 2025)
The Sitewide Notice WP WordPress plugin before 2.3 does not sanitise some of its settings before outputting them in frontend pages, allowing high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed
0
Attacker Value
Unknown
CVE-2021-24357
Disclosure Date: June 14, 2021 (last updated February 22, 2025)
In the Best Image Gallery & Responsive Photo Gallery – FooGallery WordPress plugin before 2.0.35, the Custom CSS field of each gallery is not properly sanitised or validated before being being output in the page where the gallery is embed, leading to a stored Cross-Site Scripting issue.
0
Attacker Value
Unknown
CVE-2019-19134
Disclosure Date: February 26, 2020 (last updated February 21, 2025)
The Hero Maps Premium plugin 2.2.1 and prior for WordPress is prone to unauthenticated XSS via the views/dashboard/index.php p parameter because it fails to sufficiently sanitize user-supplied input. An attacker may leverage this issue to inject HTML or arbitrary JavaScript within the browser of an unsuspecting user in the context of the affected site. This may allow the attacker to steal cookie-based tokens or to launch other attacks.
0
Attacker Value
Unknown
CVE-2019-20182
Disclosure Date: January 09, 2020 (last updated February 21, 2025)
The FooGallery plugin 1.8.12 for WordPress allow XSS via the post_title parameter.
0
Attacker Value
Unknown
CVE-2019-15778
Disclosure Date: August 29, 2019 (last updated November 27, 2024)
The woo-variation-gallery plugin before 1.1.29 for WordPress has XSS.
0
Attacker Value
Unknown
CVE-2019-14774
Disclosure Date: August 08, 2019 (last updated November 27, 2024)
The woo-variation-swatches (aka Variation Swatches for WooCommerce) plugin 1.0.61 for WordPress allows XSS via the wp-admin/admin.php?page=woo-variation-swatches-settings tab parameter.
0