Show filters
520 Total Results
Displaying 281-290 of 520
Sort by:
Attacker Value
Unknown
CVE-2022-4484
Disclosure Date: January 16, 2023 (last updated October 08, 2023)
The Social Share, Social Login and Social Comments Plugin WordPress plugin before 7.13.44 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as admins.
0
Attacker Value
Unknown
CVE-2022-4477
Disclosure Date: January 16, 2023 (last updated October 08, 2023)
The Smash Balloon Social Post Feed WordPress plugin before 4.1.6 does not validate and escapes some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as a contributor to perform Stored Cross-Site Scripting attacks against logged-in admins.
0
Attacker Value
Unknown
CVE-2022-4451
Disclosure Date: January 16, 2023 (last updated October 08, 2023)
The Social Sharing WordPress plugin before 3.3.45 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as admins.
0
Attacker Value
Unknown
CVE-2022-4198
Disclosure Date: January 02, 2023 (last updated October 08, 2023)
The WP Social Sharing WordPress plugin through 2.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).
0
Attacker Value
Unknown
CVE-2022-42098
Disclosure Date: November 22, 2022 (last updated February 24, 2025)
KLiK SocialMediaWebsite version v1.0.1 is vulnerable to SQL Injection via the profile.php.
0
Attacker Value
Unknown
CVE-2022-3246
Disclosure Date: October 25, 2022 (last updated February 24, 2025)
The Blog2Social: Social Media Auto Post & Scheduler WordPress plugin before 6.9.10 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by any authenticated users, such as subscribers
0
Attacker Value
Unknown
CVE-2022-3247
Disclosure Date: October 25, 2022 (last updated February 24, 2025)
The Blog2Social: Social Media Auto Post & Scheduler WordPress plugin before 6.9.10 does not have authorisation in an AJAX action, and does not ensure that the URL to make a request to is an external one. As a result, any authenticated users, such as subscriber could perform SSRF attacks
0
Attacker Value
Unknown
CVE-2022-2574
Disclosure Date: October 17, 2022 (last updated February 24, 2025)
The Meks Easy Social Share WordPress plugin before 1.2.8 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)
0
Attacker Value
Unknown
CVE-2022-3136
Disclosure Date: October 10, 2022 (last updated February 24, 2025)
The Social Rocket WordPress plugin before 1.3.3 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)
0
Attacker Value
Unknown
CVE-2022-2763
Disclosure Date: October 03, 2022 (last updated February 24, 2025)
The WP Socializer WordPress plugin before 7.3 does not sanitise and escape some of its Icons settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)
0