Show filters
48 Total Results
Displaying 31-40 of 48
Sort by:
Attacker Value
Unknown

CVE-2021-24734

Disclosure Date: October 18, 2021 (last updated November 28, 2024)
The Compact WP Audio Player WordPress plugin before 1.9.7 does not escape some of its shortcodes attributes, which could allow users with a role as low as Contributor to perform Stored Cross-Site Scripting attacks.
Attacker Value
Unknown

CVE-2021-24711

Disclosure Date: October 11, 2021 (last updated November 28, 2024)
The del_reistered_domains AJAX action of the Software License Manager WordPress plugin before 4.5.1 does not have any CSRF checks, and is vulnerable to a CSRF attack
Attacker Value
Unknown

CVE-2021-24560

Disclosure Date: September 13, 2021 (last updated November 28, 2024)
The Software License Manager WordPress plugin before 4.4.8 does not sanitise or escape the edit_record parameter before outputting it back in the page in the admin dashboard, leading to a Reflected Cross-Site Scripting issue
Attacker Value
Unknown

CVE-2021-24665

Disclosure Date: August 30, 2021 (last updated February 23, 2025)
The WP Video Lightbox WordPress plugin before 1.9.3 does not escape the attributes of its shortcodes, allowing users with a role as low as contributor to perform Cross-Site Scripting attacks
Attacker Value
Unknown

CVE-2021-20782

Disclosure Date: July 14, 2021 (last updated February 23, 2025)
Cross-site request forgery (CSRF) vulnerability in Software License Manager versions prior to 4.4.6 allows remote attackers to hijack the authentication of administrators via unspecified vectors.
Attacker Value
Unknown

CVE-2020-29171

Disclosure Date: February 10, 2021 (last updated February 22, 2025)
Cross-site scripting (XSS) vulnerability in admin/wp-security-blacklist-menu.php in the Tips and Tricks HQ All In One WP Security & Firewall (all-in-one-wp-security-and-firewall) plugin before 4.4.6 for WordPress.
Attacker Value
Unknown

CVE-2020-5651

Disclosure Date: October 21, 2020 (last updated February 22, 2025)
SQL injection vulnerability in Simple Download Monitor 3.8.8 and earlier allows remote attackers to execute arbitrary SQL commands via a specially crafted URL.
Attacker Value
Unknown

CVE-2020-5650

Disclosure Date: October 21, 2020 (last updated February 22, 2025)
Cross-site scripting vulnerability in Simple Download Monitor 3.8.8 and earlier allows remote attackers to inject an arbitrary script via unspecified vectors.
Attacker Value
Unknown

CVE-2019-5993

Disclosure Date: September 12, 2019 (last updated November 27, 2024)
Cross-site request forgery (CSRF) vulnerability in Category Specific RSS feed Subscription version v2.0 and earlier allows remote attackers to hijack the authentication of administrators via unspecified vectors.
Attacker Value
Unknown

CVE-2015-9310

Disclosure Date: August 14, 2019 (last updated November 27, 2024)
The all-in-one-wp-security-and-firewall plugin before 3.9.1 for WordPress has multiple SQL injection issues.
0