Show filters
47 Total Results
Displaying 41-47 of 47
Sort by:
Attacker Value
Unknown

CVE-2021-36920

Disclosure Date: January 11, 2022 (last updated October 07, 2023)
Authenticated Reflected Cross-Site Scripting (XSS) vulnerability discovered in WordPress plugin Download Monitor (versions <= 4.4.6).
Attacker Value
Unknown

CVE-2021-24786

Disclosure Date: January 03, 2022 (last updated October 07, 2023)
The Download Monitor WordPress plugin before 4.4.5 does not properly validate and escape the "orderby" GET parameter before using it in a SQL statement when viewing the logs, leading to an SQL Injection issue
Attacker Value
Unknown

CVE-2021-24908

Disclosure Date: November 29, 2021 (last updated October 07, 2023)
The Check & Log Email WordPress plugin before 1.0.4 does not escape the d parameter before outputting it back in an attribute, leading to a Reflected Cross-Site Scripting
Attacker Value
Unknown

CVE-2021-31567

Disclosure Date: October 29, 2021 (last updated October 07, 2023)
Authenticated (admin+) Arbitrary File Download vulnerability discovered in Download Monitor WordPress plugin (versions <= 4.4.6). The plugin allows arbitrary files, including sensitive configuration files such as wp-config.php, to be downloaded via the &downloadable_file_urls[0] parameter data. It's also possible to escape from the web server home directory and download any file within the OS.
Attacker Value
Unknown

CVE-2021-23174

Disclosure Date: October 29, 2021 (last updated September 17, 2024)
Authenticated (admin+) Persistent Cross-Site Scripting (XSS) vulnerability discovered in Download Monitor WordPress plugin (versions <= 4.4.6) Vulnerable parameters: &post_title, &downloadable_file_version[0].
Attacker Value
Unknown

CVE-2021-24774

Disclosure Date: October 25, 2021 (last updated November 28, 2024)
The Check & Log Email WordPress plugin before 1.0.3 does not validate and escape the "order" and "orderby" GET parameters before using them in a SQL statement when viewing logs, leading to SQL injections issues
Attacker Value
Unknown

CVE-2020-8549

Disclosure Date: February 03, 2020 (last updated October 30, 2024)
Stored XSS in the Strong Testimonials plugin before 2.40.1 for WordPress can result in an attacker performing malicious actions such as stealing session tokens.