Show filters
140 Total Results
Displaying 41-50 of 140
Sort by:
Attacker Value
Unknown

CVE-2024-31264

Disclosure Date: April 12, 2024 (last updated February 26, 2025)
Unauthenticated Cross Site Request Forgery (CSRF) in Post Views Counter <= 1.4.4 versions.
0
Attacker Value
Unknown

CVE-2023-48275

Disclosure Date: March 26, 2024 (last updated February 26, 2025)
Unrestricted Upload of File with Dangerous Type vulnerability in Trustindex.Io Widgets for Google Reviews.This issue affects Widgets for Google Reviews: from n/a through 11.0.2.
0
Attacker Value
Unknown

CVE-2024-2080

Disclosure Date: March 22, 2024 (last updated April 02, 2024)
The LiquidPoll – Polls, Surveys, NPS and Feedback Reviews plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.3.76 via the poller_list shortcode. This makes it possible for authenticated attackers, with contributor-level access and above, to extract information from polls that may be private.
0
Attacker Value
Unknown

CVE-2024-29093

Disclosure Date: March 19, 2024 (last updated February 26, 2025)
Cross-Site Request Forgery (CSRF) vulnerability in Tobias Conrad Builder for WooCommerce reviews shortcodes – ReviewShort.This issue affects Builder for WooCommerce reviews shortcodes – ReviewShort: from n/a through 1.01.3.
0
Attacker Value
Unknown

CVE-2024-29095

Disclosure Date: March 19, 2024 (last updated February 26, 2025)
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Paul Ryley Site Reviews allows Stored XSS.This issue affects Site Reviews: from n/a through 6.11.6.
0
Attacker Value
Unknown

CVE-2024-25597

Disclosure Date: March 15, 2024 (last updated February 26, 2025)
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Etoile Web Design Ultimate Reviews allows Stored XSS.This issue affects Ultimate Reviews: from n/a through 3.2.8.
Attacker Value
Unknown

CVE-2024-2293

Disclosure Date: March 13, 2024 (last updated April 01, 2024)
The Site Reviews plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the user display name in all versions up to, and including, 6.11.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with subscriber access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
0
Attacker Value
Unknown

CVE-2024-1044

Disclosure Date: February 29, 2024 (last updated February 26, 2025)
The Customer Reviews for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'submit_review' function in all versions up to, and including, 5.38.12. This makes it possible for unauthenticated attackers to submit reviews with arbitrary email addresses regardless of whether reviews are globally enabled.
0
Attacker Value
Unknown

CVE-2023-51692

Disclosure Date: February 28, 2024 (last updated February 26, 2025)
Missing Authorization vulnerability in CusRev Customer Reviews for WooCommerce.This issue affects Customer Reviews for WooCommerce: from n/a through 5.38.1.
Attacker Value
Unknown

CVE-2024-0612

Disclosure Date: February 05, 2024 (last updated February 26, 2025)
The Content Views – Post Grid, Slider, Accordion (Gutenberg Blocks and Shortcode) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 3.6.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.