Show filters
64 Total Results
Displaying 41-50 of 64
Sort by:
Attacker Value
Unknown
CVE-2022-43482
Disclosure Date: October 30, 2022 (last updated December 22, 2024)
Missing Authorization vulnerability in Appointment Booking Calendar plugin <= 1.3.69 on WordPress.
0
Attacker Value
Unknown
CVE-2022-2567
Disclosure Date: September 19, 2022 (last updated October 08, 2023)
The Form Builder CP WordPress plugin before 1.2.32 does not sanitise and escape some of its form settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)
0
Attacker Value
Unknown
CVE-2022-0389
Disclosure Date: March 07, 2022 (last updated October 07, 2023)
The WP Time Slots Booking Form WordPress plugin before 1.1.63 does not sanitise and escape Calendar names, allowing high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.
0
Attacker Value
Unknown
CVE-2021-42361
Disclosure Date: November 11, 2021 (last updated November 28, 2024)
The Contact Form Email WordPress plugin is vulnerable to Stored Cross-Site Scripting due to insufficient input validation and escaping via the name parameter found in the ~/trunk/cp-admin-int-list.inc.php file which allowed attackers with administrative user access to inject arbitrary web scripts, in versions up to and including 1.3.24. This affects multi-site installations where unfiltered_html is disabled for administrators, and sites where unfiltered_html is disabled.
0
Attacker Value
Unknown
CVE-2020-9372
Disclosure Date: March 04, 2020 (last updated February 21, 2025)
The Appointment Booking Calendar plugin before 1.3.35 for WordPress allows user input (in fields such as Description or Name) in any booking form to be any formula, which then could be exported via the Bookings list tab in /wp-admin/admin.php?page=cpabc_appointments.php. The attacker could achieve remote code execution via CSV injection.
0
Attacker Value
Unknown
CVE-2020-7228
Disclosure Date: January 22, 2020 (last updated February 21, 2025)
The Calculated Fields Form plugin through 1.0.353 for WordPress suffers from multiple Stored XSS vulnerabilities present in the input forms. These can be exploited by an authenticated user.
0
Attacker Value
Unknown
CVE-2016-10992
Disclosure Date: September 17, 2019 (last updated November 27, 2024)
The music-store plugin before 1.0.43 for WordPress has XSS via the wp-admin/admin.php?page=music-store-menu-reports from_year parameter.
0
Attacker Value
Unknown
CVE-2015-9348
Disclosure Date: August 27, 2019 (last updated November 27, 2024)
The sell-downloads plugin before 1.0.8 for WordPress has insufficient restrictions on brute-force guessing of purchase IDs.
0
Attacker Value
Unknown
CVE-2014-10395
Disclosure Date: August 27, 2019 (last updated November 27, 2024)
The cp-polls plugin before 1.0.1 for WordPress has XSS in the votes list.
0
Attacker Value
Unknown
CVE-2015-9346
Disclosure Date: August 27, 2019 (last updated November 27, 2024)
The cp-polls plugin before 1.0.5 for WordPress has XSS.
0