Show filters
68 Total Results
Displaying 51-60 of 68
Sort by:
Attacker Value
Unknown

CVE-2022-1013

Disclosure Date: May 09, 2022 (last updated February 23, 2025)
The Personal Dictionary WordPress plugin before 1.3.4 fails to properly sanitize user supplied POST data before it is being interpolated in an SQL statement and then executed, leading to a blind SQL injection vulnerability.
Attacker Value
Unknown

CVE-2022-0641

Disclosure Date: March 28, 2022 (last updated February 23, 2025)
The Popup Like box WordPress plugin before 3.6.1 does not sanitize and escape the ays_fb_tab parameter before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting.
Attacker Value
Unknown

CVE-2021-24931

Disclosure Date: December 06, 2021 (last updated February 23, 2025)
The Secure Copy Content Protection and Content Locking WordPress plugin before 2.8.2 does not escape the sccp_id parameter of the ays_sccp_results_export_file AJAX action (available to both unauthenticated and authenticated users) before using it in a SQL statement, leading to an SQL injection.
Attacker Value
Unknown

CVE-2021-26256

Disclosure Date: December 03, 2021 (last updated February 23, 2025)
Unauthenticated Stored Cross-Site Scripting (XSS) vulnerability discovered in Survey Maker WordPress plugin (versions <= 2.0.6).
Attacker Value
Unknown

CVE-2021-24651

Disclosure Date: October 11, 2021 (last updated February 23, 2025)
The Poll Maker WordPress plugin before 3.4.2 allows unauthenticated users to perform SQL injection via the ays_finish_poll AJAX action. While the result is not disclosed in the response, it is possible to use a timing attack to exfiltrate data such as password hash.
Attacker Value
Unknown

CVE-2021-24458

Disclosure Date: August 02, 2021 (last updated February 23, 2025)
The get_ays_popupboxes() and get_popup_categories() functions of the Popup box WordPress plugin before 2.3.4 did not use whitelist or validate the orderby parameter before using it in SQL statements passed to the get_results() DB calls, leading to SQL injection issues in the admin dashboard
Attacker Value
Unknown

CVE-2021-24483

Disclosure Date: August 02, 2021 (last updated February 23, 2025)
The get_poll_categories(), get_polls() and get_reports() functions in the Poll Maker WordPress plugin before 3.2.1 did not use whitelist or validate the orderby parameter before using it in SQL statements passed to the get_results() DB calls, leading to SQL injection issues in the admin dashboard
Attacker Value
Unknown

CVE-2021-24460

Disclosure Date: August 02, 2021 (last updated February 23, 2025)
The get_fb_likeboxes() function in the Popup Like box – Page Plugin WordPress plugin before 3.5.3 did not use whitelist or validate the orderby parameter before using it in SQL statements passed to the get_results() DB calls, leading to SQL injection issues in the admin dashboard
Attacker Value
Unknown

CVE-2021-24463

Disclosure Date: August 02, 2021 (last updated February 23, 2025)
The get_sliders() function in the Image Slider by Ays- Responsive Slider and Carousel WordPress plugin before 2.5.0 did not use whitelist or validate the orderby parameter before using it in SQL statements passed to the get_results() DB calls, leading to SQL injection issues in the admin dashboard
Attacker Value
Unknown

CVE-2021-24457

Disclosure Date: August 02, 2021 (last updated February 23, 2025)
The get_portfolios() and get_portfolio_attributes() functions in the class-portfolio-responsive-gallery-list-table.php and class-portfolio-responsive-gallery-attributes-list-table.php files of the Portfolio Responsive Gallery WordPress plugin before 1.1.8 did not use whitelist or validate the orderby parameter before using it in SQL statements passed to the get_results() DB calls, leading to SQL injection issues in the admin dashboard