Show filters
48 Total Results
Displaying 31-40 of 48
Sort by:
Attacker Value
Unknown
CVE-2021-24734
Disclosure Date: October 18, 2021 (last updated November 28, 2024)
The Compact WP Audio Player WordPress plugin before 1.9.7 does not escape some of its shortcodes attributes, which could allow users with a role as low as Contributor to perform Stored Cross-Site Scripting attacks.
0
Attacker Value
Unknown
CVE-2021-24711
Disclosure Date: October 11, 2021 (last updated November 28, 2024)
The del_reistered_domains AJAX action of the Software License Manager WordPress plugin before 4.5.1 does not have any CSRF checks, and is vulnerable to a CSRF attack
0
Attacker Value
Unknown
CVE-2021-24560
Disclosure Date: September 13, 2021 (last updated November 28, 2024)
The Software License Manager WordPress plugin before 4.4.8 does not sanitise or escape the edit_record parameter before outputting it back in the page in the admin dashboard, leading to a Reflected Cross-Site Scripting issue
0
Attacker Value
Unknown
CVE-2021-24665
Disclosure Date: August 30, 2021 (last updated February 23, 2025)
The WP Video Lightbox WordPress plugin before 1.9.3 does not escape the attributes of its shortcodes, allowing users with a role as low as contributor to perform Cross-Site Scripting attacks
0
Attacker Value
Unknown
CVE-2021-20782
Disclosure Date: July 14, 2021 (last updated February 23, 2025)
Cross-site request forgery (CSRF) vulnerability in Software License Manager versions prior to 4.4.6 allows remote attackers to hijack the authentication of administrators via unspecified vectors.
0
Attacker Value
Unknown
CVE-2020-29171
Disclosure Date: February 10, 2021 (last updated February 22, 2025)
Cross-site scripting (XSS) vulnerability in admin/wp-security-blacklist-menu.php in the Tips and Tricks HQ All In One WP Security & Firewall (all-in-one-wp-security-and-firewall) plugin before 4.4.6 for WordPress.
0
Attacker Value
Unknown
CVE-2020-5651
Disclosure Date: October 21, 2020 (last updated February 22, 2025)
SQL injection vulnerability in Simple Download Monitor 3.8.8 and earlier allows remote attackers to execute arbitrary SQL commands via a specially crafted URL.
0
Attacker Value
Unknown
CVE-2020-5650
Disclosure Date: October 21, 2020 (last updated February 22, 2025)
Cross-site scripting vulnerability in Simple Download Monitor 3.8.8 and earlier allows remote attackers to inject an arbitrary script via unspecified vectors.
0
Attacker Value
Unknown
CVE-2019-5993
Disclosure Date: September 12, 2019 (last updated November 27, 2024)
Cross-site request forgery (CSRF) vulnerability in Category Specific RSS feed Subscription version v2.0 and earlier allows remote attackers to hijack the authentication of administrators via unspecified vectors.
0
Attacker Value
Unknown
CVE-2015-9310
Disclosure Date: August 14, 2019 (last updated November 27, 2024)
The all-in-one-wp-security-and-firewall plugin before 3.9.1 for WordPress has multiple SQL injection issues.
0