Show filters
64 Total Results
Displaying 41-50 of 64
Sort by:
Attacker Value
Unknown

CVE-2022-43482

Disclosure Date: October 30, 2022 (last updated December 22, 2024)
Missing Authorization vulnerability in Appointment Booking Calendar plugin <= 1.3.69 on WordPress.
Attacker Value
Unknown

CVE-2022-2567

Disclosure Date: September 19, 2022 (last updated October 08, 2023)
The Form Builder CP WordPress plugin before 1.2.32 does not sanitise and escape some of its form settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)
Attacker Value
Unknown

CVE-2022-0389

Disclosure Date: March 07, 2022 (last updated October 07, 2023)
The WP Time Slots Booking Form WordPress plugin before 1.1.63 does not sanitise and escape Calendar names, allowing high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.
Attacker Value
Unknown

CVE-2021-42361

Disclosure Date: November 11, 2021 (last updated November 28, 2024)
The Contact Form Email WordPress plugin is vulnerable to Stored Cross-Site Scripting due to insufficient input validation and escaping via the name parameter found in the ~/trunk/cp-admin-int-list.inc.php file which allowed attackers with administrative user access to inject arbitrary web scripts, in versions up to and including 1.3.24. This affects multi-site installations where unfiltered_html is disabled for administrators, and sites where unfiltered_html is disabled.
0
Attacker Value
Unknown

CVE-2020-9372

Disclosure Date: March 04, 2020 (last updated February 21, 2025)
The Appointment Booking Calendar plugin before 1.3.35 for WordPress allows user input (in fields such as Description or Name) in any booking form to be any formula, which then could be exported via the Bookings list tab in /wp-admin/admin.php?page=cpabc_appointments.php. The attacker could achieve remote code execution via CSV injection.
Attacker Value
Unknown

CVE-2020-7228

Disclosure Date: January 22, 2020 (last updated February 21, 2025)
The Calculated Fields Form plugin through 1.0.353 for WordPress suffers from multiple Stored XSS vulnerabilities present in the input forms. These can be exploited by an authenticated user.
Attacker Value
Unknown

CVE-2016-10992

Disclosure Date: September 17, 2019 (last updated November 27, 2024)
The music-store plugin before 1.0.43 for WordPress has XSS via the wp-admin/admin.php?page=music-store-menu-reports from_year parameter.
Attacker Value
Unknown

CVE-2015-9348

Disclosure Date: August 27, 2019 (last updated November 27, 2024)
The sell-downloads plugin before 1.0.8 for WordPress has insufficient restrictions on brute-force guessing of purchase IDs.
0
Attacker Value
Unknown

CVE-2014-10395

Disclosure Date: August 27, 2019 (last updated November 27, 2024)
The cp-polls plugin before 1.0.1 for WordPress has XSS in the votes list.
0
Attacker Value
Unknown

CVE-2015-9346

Disclosure Date: August 27, 2019 (last updated November 27, 2024)
The cp-polls plugin before 1.0.5 for WordPress has XSS.
0