Show filters
47 Total Results
Displaying 41-47 of 47
Sort by:
Attacker Value
Unknown
CVE-2021-36920
Disclosure Date: January 11, 2022 (last updated October 07, 2023)
Authenticated Reflected Cross-Site Scripting (XSS) vulnerability discovered in WordPress plugin Download Monitor (versions <= 4.4.6).
0
Attacker Value
Unknown
CVE-2021-24786
Disclosure Date: January 03, 2022 (last updated October 07, 2023)
The Download Monitor WordPress plugin before 4.4.5 does not properly validate and escape the "orderby" GET parameter before using it in a SQL statement when viewing the logs, leading to an SQL Injection issue
0
Attacker Value
Unknown
CVE-2021-24908
Disclosure Date: November 29, 2021 (last updated October 07, 2023)
The Check & Log Email WordPress plugin before 1.0.4 does not escape the d parameter before outputting it back in an attribute, leading to a Reflected Cross-Site Scripting
0
Attacker Value
Unknown
CVE-2021-31567
Disclosure Date: October 29, 2021 (last updated October 07, 2023)
Authenticated (admin+) Arbitrary File Download vulnerability discovered in Download Monitor WordPress plugin (versions <= 4.4.6). The plugin allows arbitrary files, including sensitive configuration files such as wp-config.php, to be downloaded via the &downloadable_file_urls[0] parameter data. It's also possible to escape from the web server home directory and download any file within the OS.
0
Attacker Value
Unknown
CVE-2021-23174
Disclosure Date: October 29, 2021 (last updated September 17, 2024)
Authenticated (admin+) Persistent Cross-Site Scripting (XSS) vulnerability discovered in Download Monitor WordPress plugin (versions <= 4.4.6) Vulnerable parameters: &post_title, &downloadable_file_version[0].
0
Attacker Value
Unknown
CVE-2021-24774
Disclosure Date: October 25, 2021 (last updated November 28, 2024)
The Check & Log Email WordPress plugin before 1.0.3 does not validate and escape the "order" and "orderby" GET parameters before using them in a SQL statement when viewing logs, leading to SQL injections issues
0
Attacker Value
Unknown
CVE-2020-8549
Disclosure Date: February 03, 2020 (last updated October 30, 2024)
Stored XSS in the Strong Testimonials plugin before 2.40.1 for WordPress can result in an attacker performing malicious actions such as stealing session tokens.
0