Show filters
82 Total Results
Displaying 31-40 of 82
Sort by:
Attacker Value
Unknown
CVE-2023-6985
Disclosure Date: February 05, 2024 (last updated February 14, 2024)
The 10Web AI Assistant – AI content writing assistant plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the install_plugin AJAX action in all versions up to, and including, 1.0.18. This makes it possible for authenticated attackers, with subscriber-level access and above, to install arbitrary plugins that can be used to gain further access to a compromised site.
0
Attacker Value
Unknown
CVE-2024-0667
Disclosure Date: January 27, 2024 (last updated February 01, 2024)
The Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.15.21. This is due to missing or incorrect nonce validation on the 'execute' function. This makes it possible for unauthenticated attackers to execute arbitrary methods in the 'BoosterController' class via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
0
Attacker Value
Unknown
CVE-2023-6924
Disclosure Date: January 11, 2024 (last updated January 19, 2024)
The Photo Gallery by 10Web plugin for WordPress is vulnerable to Stored Cross-Site Scripting via widgets in versions up to, and including, 1.8.18 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with administrator-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. It can also be exploited with a contributor-level permission with a page builder plugin.
0
Attacker Value
Unknown
CVE-2023-5559
Disclosure Date: November 27, 2023 (last updated December 01, 2023)
The 10Web Booster WordPress plugin before 2.24.18 does not validate the option name given to some AJAX actions, allowing unauthenticated users to delete arbitrary options from the database, leading to denial of service.
0
Attacker Value
Unknown
CVE-2023-34375
Disclosure Date: November 16, 2023 (last updated November 21, 2023)
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in 10Web SEO by 10Web plugin <= 1.2.9 versions.
0
Attacker Value
Unknown
CVE-2023-45071
Disclosure Date: October 18, 2023 (last updated October 26, 2023)
Unauth. Stored Cross-Site Scripting (XSS) vulnerability in 10Web Form Builder Team Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder plugin <= 1.15.18 versions.
0
Attacker Value
Unknown
CVE-2023-45070
Disclosure Date: October 18, 2023 (last updated October 26, 2023)
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in 10Web Form Builder Team Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder plugin <= 1.15.18 versions.
0
Attacker Value
Unknown
CVE-2023-4666
Disclosure Date: October 16, 2023 (last updated October 21, 2023)
The Form Maker by 10Web WordPress plugin before 1.15.20 does not validate signatures when creating them on the server from user input, allowing unauthenticated users to create arbitrary files and lead to RCE
0
Attacker Value
Unknown
CVE-2023-2122
Disclosure Date: August 16, 2023 (last updated October 08, 2023)
The Image Optimizer by 10web WordPress plugin before 1.0.27 does not sanitise and escape the iowd_tabs_active parameter before rendering it in the plugin admin panel, leading to a reflected Cross-Site Scripting vulnerability, allowing an attacker to trick a logged in admin to execute arbitrary javascript by clicking a link.
0
Attacker Value
Unknown
CVE-2020-36756
Disclosure Date: July 12, 2023 (last updated November 09, 2023)
The 10WebAnalytics plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.2.8. This is due to missing or incorrect nonce validation on the create_csv_file() function. This makes it possible for unauthenticated attackers to create a CSV file via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
0