Show filters
71 Total Results
Displaying 51-60 of 71
Sort by:
Attacker Value
Unknown

CVE-2023-23987

Disclosure Date: April 06, 2023 (last updated November 08, 2023)
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in WPEverest User Registration plugin <= 2.3.0 versions.
Attacker Value
Unknown

CVE-2022-38971

Disclosure Date: March 16, 2023 (last updated November 08, 2023)
Stored Cross-Site Scripting (XSS) vulnerability in ThemeKraft Post Form – Registration Form – Profile Form for User Profiles and Content Forms for User Submissions plugin <= 2.7.5 versions.
Attacker Value
Unknown

CVE-2022-4831

Disclosure Date: January 30, 2023 (last updated October 08, 2023)
The Custom User Profile Fields for User Registration WordPress plugin before 1.8.1 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as admins.
Attacker Value
Unknown

CVE-2022-3912

Disclosure Date: December 12, 2022 (last updated October 08, 2023)
The User Registration WordPress plugin before 2.2.4.1 does not properly restrict the files to be uploaded via an AJAX action available to both unauthenticated and authenticated users, which could allow unauthenticated users to upload PHP files for example.
Attacker Value
Unknown

CVE-2022-43097

Disclosure Date: December 05, 2022 (last updated October 08, 2023)
Phpgurukul User Registration & User Management System v3.0 was discovered to contain multiple stored cross-site scripting (XSS) vulnerabilities via the firstname and lastname parameters of the registration form & login pages.
Attacker Value
Unknown

CVE-2021-44096

Disclosure Date: June 02, 2022 (last updated February 23, 2025)
EGavilan Media User-Registration-and-Login-System-With-Admin-Panel 1.0 is vulnerable to SQL Injection via profile_action - update_user. This allows a remote attacker to compromise Application SQL database.
Attacker Value
Unknown

CVE-2021-24955

Disclosure Date: December 13, 2021 (last updated February 23, 2025)
The User Registration, Login Form, User Profile & Membership WordPress plugin before 3.2.3 does not escape the data parameter of the pp_get_forms_by_builder_type AJAX action before outputting it back in an attribute, leading to a Reflected Cross-Site Scripting issue
Attacker Value
Unknown

CVE-2021-24954

Disclosure Date: December 13, 2021 (last updated February 23, 2025)
The User Registration, Login Form, User Profile & Membership WordPress plugin before 3.2.3 does not sanitise and escape the ppress_cc_data parameter before outputting it back in an attribute of an admin dashboard page, leading to a Reflected Cross-Site Scripting issue
Attacker Value
Unknown

CVE-2020-23051

Disclosure Date: October 22, 2021 (last updated February 23, 2025)
Phpgurukul User Registration & User Management System v2.0 was discovered to contain multiple stored cross-site scripting (XSS) vulnerabilities via the firstname and lastname parameters of the registration form & loginsystem input fields.
Attacker Value
Unknown

CVE-2021-24654

Disclosure Date: October 04, 2021 (last updated February 23, 2025)
The User Registration WordPress plugin before 2.0.2 does not properly sanitise the user_registration_profile_pic_url value when submitted directly via the user_registration_update_profile_details AJAX action. This could allow any authenticated user, such as subscriber, to perform Stored Cross-Site attacks when their profile is viewed