Show filters
39 Total Results
Displaying 31-39 of 39
Sort by:
Attacker Value
Unknown

CVE-2022-2245

Disclosure Date: August 01, 2022 (last updated October 08, 2023)
The Counter Box WordPress plugin before 1.2.1 is lacking CSRF check when activating and deactivating counters, which could allow attackers to make a logged in admin perform such actions via CSRF attacks
Attacker Value
Unknown

CVE-2022-29446

Disclosure Date: May 16, 2022 (last updated February 23, 2025)
Authenticated (administrator or higher role) Local File Inclusion (LFI) vulnerability in Wow-Company's Counter Box plugin <= 1.1.1 at WordPress.
Attacker Value
Unknown

CVE-2022-29447

Disclosure Date: May 16, 2022 (last updated February 23, 2025)
Authenticated (administrator or higher user role) Local File Inclusion (LFI) vulnerability in Wow-Company's Hover Effects plugin <= 2.1 at WordPress.
Attacker Value
Unknown

CVE-2021-25064

Disclosure Date: March 28, 2022 (last updated February 23, 2025)
The Wow Countdowns WordPress plugin through 3.1.2 does not sanitize user input into the 'did' parameter and uses it in a SQL statement, leading to an authenticated SQL Injection.
Attacker Value
Unknown

CVE-2021-25054

Disclosure Date: January 10, 2022 (last updated February 23, 2025)
The WPcalc WordPress plugin through 2.1 does not sanitize user input into the 'did' parameter and uses it in a SQL statement, leading to an authenticated SQL Injection vulnerability.
Attacker Value
Unknown

CVE-2021-25053

Disclosure Date: January 10, 2022 (last updated February 23, 2025)
The WP Coder WordPress plugin before 2.5.2 within the wow-company admin menu page allows to include() arbitrary file with PHP extension (as well as with data:// or http:// protocols), thus leading to CSRF RCE.
Attacker Value
Unknown

CVE-2021-25052

Disclosure Date: January 10, 2022 (last updated February 23, 2025)
The Button Generator WordPress plugin before 2.3.3 within the wow-company admin menu page allows to include() arbitrary file with PHP extension (as well as with data:// or http:// protocols), thus leading to CSRF RCE.
Attacker Value
Unknown

CVE-2021-25051

Disclosure Date: January 10, 2022 (last updated February 23, 2025)
The Modal Window WordPress plugin before 5.2.2 within the wow-company admin menu page allows to include() arbitrary file with PHP extension (as well as with data:// or http:// protocols), thus leading to CSRF RCE.
Attacker Value
Unknown

CVE-2021-24628

Disclosure Date: November 08, 2021 (last updated February 23, 2025)
The Wow Forms WordPress plugin through 3.1.3 does not sanitise or escape a 'did' GET parameter before using it in a SQL statement, when deleting a form in the admin dashboard, leading to an authenticated SQL injection