Show filters
25 Total Results
Displaying 21-25 of 25
Sort by:
Attacker Value
Unknown
CVE-2023-23685
Disclosure Date: April 04, 2023 (last updated November 08, 2023)
Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in RadiusTheme Portfolio – WordPress Portfolio plugin <= 2.8.10 versions.
0
Attacker Value
Unknown
CVE-2022-2655
Disclosure Date: September 16, 2022 (last updated September 28, 2024)
The Classified Listing Pro WordPress plugin before 2.0.20 does not escape a generated URL before outputting it back in an attribute in an admin page, leading to a Reflected Cross-Site Scripting
0
Attacker Value
Unknown
CVE-2022-2654
Disclosure Date: September 16, 2022 (last updated September 28, 2024)
The Classima WordPress theme before 2.1.11 and some of its required plugins (Classified Listing before 2.2.14, Classified Listing Pro before 2.0.20, Classified Listing Store & Membership before 1.4.20 and Classima Core before 1.10) do not escape a parameter before outputting it back in attributes, leading to Reflected Cross-Site Scripting
0
Attacker Value
Unknown
CVE-2022-2557
Disclosure Date: August 22, 2022 (last updated October 08, 2023)
The Team WordPress plugin before 4.1.2 contains a file which could allow any authenticated users to download arbitrary files from the server via a path traversal vector. Furthermore, the file will also be deleted after its content is returned to the user
0
Attacker Value
Unknown
CVE-2021-24742
Disclosure Date: November 01, 2021 (last updated November 28, 2024)
The Logo Slider and Showcase WordPress plugin before 1.3.37 allows Editor users to update the plugin's settings via the rtWLSSettings AJAX action because it uses a nonce for authorisation instead of a capability check.
0