Show filters
520 Total Results
Displaying 331-340 of 520
Sort by:
Attacker Value
Unknown
CVE-2021-24867
Disclosure Date: February 21, 2022 (last updated February 23, 2025)
Numerous Plugins and Themes from the AccessPress Themes (aka Access Keys) vendor are backdoored due to their website being compromised. Only plugins and themes downloaded via the vendor website are affected, and those hosted on wordpress.org are not. However, all of them were updated or removed to avoid any confusion
0
Attacker Value
Unknown
CVE-2021-36848
Disclosure Date: February 10, 2022 (last updated February 23, 2025)
Authenticated (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Social Media Feather (WordPress plugin) versions <= 2.0.4
0
Attacker Value
Unknown
CVE-2021-25072
Disclosure Date: February 01, 2022 (last updated February 23, 2025)
The NextScripts: Social Networks Auto-Poster WordPress plugin before 4.3.25 does not have CSRF check in place when deleting items, allowing attacker to make a logged in admin delete arbitrary posts via a CSRF attack
0
Attacker Value
Unknown
CVE-2021-24975
Disclosure Date: February 01, 2022 (last updated February 23, 2025)
The NextScripts: Social Networks Auto-Poster WordPress plugin before 4.3.24 does not sanitise and escape logged requests before outputting them in the related admin dashboard, leading to an Unauthenticated Stored Cross-Site Scripting issue
0
Attacker Value
Unknown
CVE-2021-25065
Disclosure Date: January 17, 2022 (last updated February 23, 2025)
The Smash Balloon Social Post Feed WordPress plugin before 4.1.1 was affected by a reflected XSS in custom-facebook-feed in cff-top admin page.
0
Attacker Value
Unknown
CVE-2021-25047
Disclosure Date: January 10, 2022 (last updated February 23, 2025)
The 10Web Social Photo Feed WordPress plugin before 1.4.29 was affected by a reflected Cross-Site Scripting (XSS) vulnerability in the wdi_apply_changes admin page, allowing an attacker to perform such attack against any logged in users
0
Attacker Value
Unknown
CVE-2021-24956
Disclosure Date: December 21, 2021 (last updated February 23, 2025)
The Blog2Social: Social Media Auto Post & Scheduler WordPress plugin before 6.8.7 does not sanitise and escape the b2sShowByDate parameter before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting issue
0
Attacker Value
Unknown
CVE-2021-24918
Disclosure Date: November 29, 2021 (last updated February 23, 2025)
The Smash Balloon Social Post Feed WordPress plugin before 4.0.1 did not have any privilege or nonce validation before saving the plugin's setting. As a result, any logged-in user on a vulnerable site could update the settings and store rogue JavaScript on each of its posts and pages.
0
Attacker Value
Unknown
CVE-2021-38356
Disclosure Date: November 28, 2021 (last updated February 23, 2025)
The NextScripts: Social Networks Auto-Poster <= 4.3.20 WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the $_REQUEST['page'] parameter which is echoed out on inc/nxs_class_snap.php by supplying the appropriate value 'nxssnap-post' to load the page in $_GET['page'] along with malicious JavaScript in $_POST['page'].
0
Attacker Value
Unknown
CVE-2021-36843
Disclosure Date: October 27, 2021 (last updated February 23, 2025)
Authenticated Stored Cross-Site Scripting (XSS) vulnerability discovered in WordPress Floating Social Media Icon plugin (versions <= 4.3.5) Social Media Configuration form. Requires high role user like admin.
0