Show filters
519 Total Results
Displaying 261-270 of 519
Sort by:
Attacker Value
Unknown

CVE-2023-25056

Disclosure Date: May 23, 2023 (last updated February 25, 2025)
Cross-Site Request Forgery (CSRF) vulnerability in SlickRemix Feed Them Social plugin <= 3.0.2 versions.
Attacker Value
Unknown

CVE-2023-23706

Disclosure Date: May 23, 2023 (last updated February 25, 2025)
Cross-Site Request Forgery (CSRF) vulnerability in miniOrange WordPress Social Login and Register (Discord, Google, Twitter, LinkedIn) plugin <= 7.5.14 versions.
Attacker Value
Unknown

CVE-2023-2704

Disclosure Date: May 19, 2023 (last updated February 25, 2025)
The BP Social Connect plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 1.5. This is due to insufficient verification on the user being supplied during a Facebook login through the plugin. This makes it possible for unauthenticated attackers to log in as any existing user on the site, such as an administrator, if they have access to the email.
Attacker Value
Unknown

CVE-2023-23688

Disclosure Date: May 15, 2023 (last updated February 24, 2025)
Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Sumo Social Share Boost plugin <= 4.4 versions.
Attacker Value
Unknown

CVE-2023-23733

Disclosure Date: May 09, 2023 (last updated February 24, 2025)
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Joel James Lazy Social Comments plugin <= 2.0.4 versions.
Attacker Value
Unknown

CVE-2023-25792

Disclosure Date: May 03, 2023 (last updated February 24, 2025)
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in XiaoMac WP Open Social plugin <= 5.0 versions.
Attacker Value
Unknown

CVE-2023-23710

Disclosure Date: April 25, 2023 (last updated February 24, 2025)
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in miniOrange WordPress Social Login and Register (Discord, Google, Twitter, LinkedIn) plugin <= 7.5.14 versions.
Attacker Value
Unknown

CVE-2023-23972

Disclosure Date: April 06, 2023 (last updated February 24, 2025)
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Smplug-in Social Like Box and Page by WpDevArt plugin <= 0.8.39 versions.
Attacker Value
Unknown

CVE-2023-24381

Disclosure Date: March 20, 2023 (last updated February 24, 2025)
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in NsThemes Advanced Social Pixel plugin <= 2.1.1 versions.
Attacker Value
Unknown

CVE-2022-38063

Disclosure Date: March 16, 2023 (last updated February 24, 2025)
Cross-Site Request Forgery (CSRF) vulnerability in Social Login WP plugin <= 5.0.0.0 versions.