Show filters
278 Total Results
Displaying 251-260 of 278
Sort by:
Attacker Value
Unknown

CVE-2023-22707

Disclosure Date: March 27, 2023 (last updated February 24, 2025)
Auth. (author+) Cross-Site Scripting (XSS) vulnerability in Wpsoul Greenshift – animation and page builder blocks plugin <= 4.9.9 versions.
Attacker Value
Unknown

CVE-2023-0378

Disclosure Date: February 21, 2023 (last updated October 08, 2023)
The Greenshift WordPress plugin before 5.0 does not validate and escape some of its block options before outputting them back in a page/post where the block is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.
Attacker Value
Unknown

CVE-2022-4653

Disclosure Date: January 16, 2023 (last updated October 08, 2023)
The Greenshift WordPress plugin before 4.8.9 does not validate and escape one of its shortcode attributes, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attack.
Attacker Value
Unknown

CVE-2022-36292

Disclosure Date: August 10, 2022 (last updated February 24, 2025)
Cross-Site Request Forgery (CSRF) vulnerabilities in WPChill Gallery PhotoBlocks plugin <= 1.2.6 at WordPress.
Attacker Value
Unknown

CVE-2022-37407

Disclosure Date: August 10, 2022 (last updated February 24, 2025)
Multiple Authenticated Stored Cross-Site Scripting (XSS) vulnerabilities in WPChill Gallery PhotoBlocks plugin <= 1.2.6 at WordPress.
Attacker Value
Unknown

CVE-2017-20090

Disclosure Date: June 23, 2022 (last updated February 23, 2025)
A vulnerability was found in Global Content Blocks Plugin 2.1.5. It has been declared as problematic. This vulnerability affects unknown code. The manipulation leads to cross-site request forgery. The attack can be initiated remotely.
Attacker Value
Unknown

CVE-2022-0448

Disclosure Date: March 07, 2022 (last updated February 23, 2025)
The CP Blocks WordPress plugin before 1.0.15 does not sanitise and escape its "License ID" settings, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html is disallowed.
Attacker Value
Unknown

CVE-2021-24751

Disclosure Date: November 29, 2021 (last updated February 23, 2025)
The GenerateBlocks WordPress plugin before 1.4.0 does not validate the generateblocks/container block's tagName attribute, which could allow users with a role as low as contributor to perform Cross-Site Scripting attacks.
Attacker Value
Unknown

CVE-2021-24677

Disclosure Date: October 18, 2021 (last updated February 23, 2025)
The Find My Blocks WordPress plugin before 3.4.0 does not have authorisation checks in its REST API, which could allow unauthenticated users to enumerate private posts' titles.
Attacker Value
Unknown

CVE-2021-24652

Disclosure Date: September 27, 2021 (last updated February 23, 2025)
The PostX – Gutenberg Blocks for Post Grid WordPress plugin before 2.4.10 performs incorrect checks before allowing any logged in user to perform some ajax based requests, allowing any user to modify, delete or add ultp_options values.