Show filters
520 Total Results
Displaying 281-290 of 520
Sort by:
Attacker Value
Unknown

CVE-2022-4484

Disclosure Date: January 16, 2023 (last updated October 08, 2023)
The Social Share, Social Login and Social Comments Plugin WordPress plugin before 7.13.44 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as admins.
Attacker Value
Unknown

CVE-2022-4477

Disclosure Date: January 16, 2023 (last updated October 08, 2023)
The Smash Balloon Social Post Feed WordPress plugin before 4.1.6 does not validate and escapes some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as a contributor to perform Stored Cross-Site Scripting attacks against logged-in admins.
Attacker Value
Unknown

CVE-2022-4451

Disclosure Date: January 16, 2023 (last updated October 08, 2023)
The Social Sharing WordPress plugin before 3.3.45 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as admins.
Attacker Value
Unknown

CVE-2022-4198

Disclosure Date: January 02, 2023 (last updated October 08, 2023)
The WP Social Sharing WordPress plugin through 2.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).
Attacker Value
Unknown

CVE-2022-42098

Disclosure Date: November 22, 2022 (last updated February 24, 2025)
KLiK SocialMediaWebsite version v1.0.1 is vulnerable to SQL Injection via the profile.php.
Attacker Value
Unknown

CVE-2022-3246

Disclosure Date: October 25, 2022 (last updated February 24, 2025)
The Blog2Social: Social Media Auto Post & Scheduler WordPress plugin before 6.9.10 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by any authenticated users, such as subscribers
Attacker Value
Unknown

CVE-2022-3247

Disclosure Date: October 25, 2022 (last updated February 24, 2025)
The Blog2Social: Social Media Auto Post & Scheduler WordPress plugin before 6.9.10 does not have authorisation in an AJAX action, and does not ensure that the URL to make a request to is an external one. As a result, any authenticated users, such as subscriber could perform SSRF attacks
Attacker Value
Unknown

CVE-2022-2574

Disclosure Date: October 17, 2022 (last updated February 24, 2025)
The Meks Easy Social Share WordPress plugin before 1.2.8 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)
Attacker Value
Unknown

CVE-2022-3136

Disclosure Date: October 10, 2022 (last updated February 24, 2025)
The Social Rocket WordPress plugin before 1.3.3 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)
Attacker Value
Unknown

CVE-2022-2763

Disclosure Date: October 03, 2022 (last updated February 24, 2025)
The WP Socializer WordPress plugin before 7.3 does not sanitise and escape some of its Icons settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)