Show filters
44 Total Results
Displaying 41-44 of 44
Sort by:
Attacker Value
Unknown
CVE-2022-2351
Disclosure Date: September 16, 2022 (last updated October 08, 2023)
The Post SMTP Mailer/Email Log WordPress plugin before 2.1.4 does not escape some of its settings before outputting them in the admins dashboard, allowing high privilege users to perform Cross-Site Scripting attacks against other users even when the unfiltered_html capability is disallowed.
0
Attacker Value
Unknown
CVE-2022-1301
Disclosure Date: July 04, 2022 (last updated October 07, 2023)
The WP Contact Slider WordPress plugin before 2.4.7 does not sanitize and escape the Text to Display settings of sliders, which could allow high privileged users such as editor and above to perform Cross-Site Scripting attacks even when the unfiltered_html is disallowed
0
Attacker Value
Unknown
CVE-2022-1625
Disclosure Date: June 27, 2022 (last updated October 07, 2023)
The New User Approve WordPress plugin before 2.4 does not have CSRF check in place when updating its settings and adding invitation codes, which could allow attackers to add invitation codes (for bypassing the provided restrictions) and to change plugin settings by tricking admin users into visiting specially crafted websites.
0
Attacker Value
Unknown
CVE-2024-13713
Last updated February 21, 2025
The WPExperts Square For GiveWP plugin for WordPress is vulnerable to SQL Injection via the 'post' parameter in all versions up to, and including, 1.3.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with Subscriber-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.
0