Show filters
115 Total Results
Displaying 41-50 of 115
Sort by:
Attacker Value
Unknown

CVE-2023-24392

Disclosure Date: May 10, 2023 (last updated February 24, 2025)
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in I Thirteen Web Solution Full Width Banner Slider Wp plugin <= 1.1.7 versions.
Attacker Value
Unknown

CVE-2022-45818

Disclosure Date: May 04, 2023 (last updated February 24, 2025)
Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in WP OnlineSupport, Essential Plugin Hero Banner Ultimate plugin <= 1.3.4 versions.
Attacker Value
Unknown

CVE-2023-28661

Disclosure Date: March 22, 2023 (last updated February 24, 2025)
The WP Popup Banners WordPress Plugin, version <= 1.2.5, is affected by an authenticated SQL injection vulnerability in the 'value' parameter in the get_popup_data action.
Attacker Value
Unknown

CVE-2023-1471

Disclosure Date: March 17, 2023 (last updated November 08, 2023)
The WP Popup Banners plugin for WordPress is vulnerable to SQL Injection via the 'banner_id' parameter in versions up to, and including, 1.2.5 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers with minimal permissions, such as a subscrber, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.
Attacker Value
Unknown

CVE-2022-43469

Disclosure Date: February 14, 2023 (last updated February 24, 2025)
Cross-Site Request Forgery (CSRF) vulnerability in Orchestrated Corona Virus (COVID-19) Banner & Live Data plugin <= 1.7.0.6 versions.
Attacker Value
Unknown

CVE-2022-4507

Disclosure Date: January 16, 2023 (last updated October 08, 2023)
The Real Cookie Banner WordPress plugin before 3.4.10 does not validate and escapes some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as a contributor to perform Stored Cross-Site Scripting attacks against logged-in admins.
Attacker Value
Unknown

CVE-2022-26366

Disclosure Date: November 30, 2022 (last updated February 24, 2025)
Cross-Site Request Forgery (CSRF) in AdRotate Banner Manager Plugin <= 5.9 on WordPress.
Attacker Value
Unknown

CVE-2022-3823

Disclosure Date: November 28, 2022 (last updated October 08, 2023)
The Beautiful Cookie Consent Banner WordPress plugin before 2.9.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).
Attacker Value
Unknown

CVE-2022-2515

Disclosure Date: September 06, 2022 (last updated February 24, 2025)
The Simple Banner plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `pro_version_activation_code` parameter in versions up to, and including, 2.11.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, including those without administrative capabilities when access is granted to those users, to inject arbitrary web scripts in page that will execute whenever a user role having access to "Simple Banner" accesses the plugin's settings.
Attacker Value
Unknown

CVE-2022-2233

Disclosure Date: September 06, 2022 (last updated February 24, 2025)
The Banner Cycler plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including 1.4. This is due to missing nonce protection on the pabc_admin_slides_postback() function found in the ~/admin/admin.php file. This makes it possible for unauthenticated attackers to inject malicious web scripts into the page, granted they can trick a site’s administrator into performing an action such as clicking on a link