Show filters
88 Total Results
Displaying 51-60 of 88
Sort by:
Attacker Value
Unknown
CVE-2022-3911
Disclosure Date: January 02, 2023 (last updated February 24, 2025)
The iubenda WordPress plugin before 3.3.3 does does not have authorisation and CSRF in an AJAX action, and does not ensure that the options to be updated belong to the plugin as long as they are arrays. As a result, any authenticated users, such as subscriber can grant themselves any privileges, such as edit_plugins etc
0
Attacker Value
Unknown
CVE-2022-3823
Disclosure Date: November 28, 2022 (last updated October 08, 2023)
The Beautiful Cookie Consent Banner WordPress plugin before 2.9.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).
0
Attacker Value
Unknown
CVE-2022-44727
Disclosure Date: November 10, 2022 (last updated February 24, 2025)
The EU Cookie Law GDPR (Banner + Blocker) module before 2.1.3 for PrestaShop allows SQL Injection via a cookie ( lgcookieslaw or __lglaw ).
0
Attacker Value
Unknown
CVE-2022-24065
Disclosure Date: June 03, 2022 (last updated February 23, 2025)
The package cookiecutter before 2.1.1 are vulnerable to Command Injection via hg argument injection. When calling the cookiecutter function from Python code with the checkout parameter, it is passed to the hg checkout command in a way that additional flags can be set. The additional flags can be used to perform a command injection.
0
Attacker Value
Unknown
CVE-2022-0445
Disclosure Date: March 07, 2022 (last updated February 23, 2025)
The WordPress Real Cookie Banner: GDPR (DSGVO) & ePrivacy Cookie Consent WordPress plugin before 2.14.2 does not have CSRF checks in place when resetting its settings, allowing attackers to make a logged in admin reset them via a CSRF attack
0
Attacker Value
Unknown
CVE-2022-23395
Disclosure Date: March 02, 2022 (last updated February 23, 2025)
jQuery Cookie 1.4.1 is affected by prototype pollution, which can lead to DOM cross-site scripting (XSS).
0
Attacker Value
Unknown
CVE-2021-24867
Disclosure Date: February 21, 2022 (last updated February 23, 2025)
Numerous Plugins and Themes from the AccessPress Themes (aka Access Keys) vendor are backdoored due to their website being compromised. Only plugins and themes downloaded via the vendor website are affected, and those hosted on wordpress.org are not. However, all of them were updated or removed to avoid any confusion
0
Attacker Value
Unknown
CVE-2021-24858
Disclosure Date: January 24, 2022 (last updated February 23, 2025)
The Cookie Notification Plugin for WordPress plugin before 1.0.9 does not sanitise or escape the id GET parameter before using it in a SQL statement, when retrieving the setting to edit in the admin dashboard, leading to an authenticated SQL Injection
0
Attacker Value
Unknown
CVE-2021-36889
Disclosure Date: December 17, 2021 (last updated February 23, 2025)
Multiple Stored Authenticated Cross-Site Scripting (XSS) vulnerabilities were discovered in tarteaucitron.js – Cookies legislation & GDPR WordPress plugin (versions <= 1.6).
0
Attacker Value
Unknown
CVE-2021-36887
Disclosure Date: December 09, 2021 (last updated February 23, 2025)
Cross-Site Request Forgery (CSRF) vulnerability leading to Cross-Site Scripting (XSS) discovered in tarteaucitron.js – Cookies legislation & GDPR WordPress plugin (versions <= 1.5.4), vulnerable parameters "tarteaucitronEmail" and "tarteaucitronPass".
0