Show filters
91 Total Results
Displaying 31-40 of 91
Sort by:
Attacker Value
Unknown

CVE-2024-3731

Disclosure Date: April 19, 2024 (last updated February 06, 2025)
The Customer Reviews for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 's' parameter in all versions up to, and including, 5.47.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.
0
Attacker Value
Unknown

CVE-2024-3869

Disclosure Date: April 16, 2024 (last updated February 06, 2025)
The Customer Reviews for WooCommerce plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'woocommerce_json_search_coupons' function . This makes it possible for attackers with subscriber level access to view coupon codes.
0
Attacker Value
Unknown

CVE-2024-3243

Disclosure Date: April 16, 2024 (last updated February 06, 2025)
The Customer Reviews for WooCommerce plugin for WordPress is vulnerable to unauthorized email sending due to a missing capability check on the send_test_email() function in all versions up to, and including, 5.46.0. This makes it possible for authenticated attackers, with subscriber-level access and above, to send arbitrary test emails.
0
Attacker Value
Unknown

CVE-2024-1849

Disclosure Date: April 15, 2024 (last updated April 15, 2024)
The WP Customer Reviews WordPress plugin before 3.7.1 does not validate a parameter allowing contributor and above users to redirect a page to a malicious URL
0
Attacker Value
Unknown

CVE-2023-48275

Disclosure Date: March 26, 2024 (last updated April 02, 2024)
Unrestricted Upload of File with Dangerous Type vulnerability in Trustindex.Io Widgets for Google Reviews.This issue affects Widgets for Google Reviews: from n/a through 11.0.2.
0
Attacker Value
Unknown

CVE-2024-2080

Disclosure Date: March 22, 2024 (last updated April 02, 2024)
The LiquidPoll – Polls, Surveys, NPS and Feedback Reviews plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.3.76 via the poller_list shortcode. This makes it possible for authenticated attackers, with contributor-level access and above, to extract information from polls that may be private.
0
Attacker Value
Unknown

CVE-2024-29093

Disclosure Date: March 19, 2024 (last updated January 05, 2025)
Cross-Site Request Forgery (CSRF) vulnerability in Tobias Conrad Builder for WooCommerce reviews shortcodes – ReviewShort.This issue affects Builder for WooCommerce reviews shortcodes – ReviewShort: from n/a through 1.01.3.
0
Attacker Value
Unknown

CVE-2024-29095

Disclosure Date: March 19, 2024 (last updated January 05, 2025)
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Paul Ryley Site Reviews allows Stored XSS.This issue affects Site Reviews: from n/a through 6.11.6.
0
Attacker Value
Unknown

CVE-2024-25597

Disclosure Date: March 15, 2024 (last updated January 24, 2025)
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Etoile Web Design Ultimate Reviews allows Stored XSS.This issue affects Ultimate Reviews: from n/a through 3.2.8.
Attacker Value
Unknown

CVE-2024-2293

Disclosure Date: March 13, 2024 (last updated April 01, 2024)
The Site Reviews plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the user display name in all versions up to, and including, 6.11.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with subscriber access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
0