Show filters
95 Total Results
Displaying 61-70 of 95
Sort by:
Attacker Value
Unknown

CVE-2023-5238

Disclosure Date: October 31, 2023 (last updated November 09, 2023)
The EventPrime WordPress plugin before 3.2.0 does not sanitise and escape a parameter before outputting it back in the page, leading to an HTML Injection on the plugin in the search area of the website.
Attacker Value
Unknown

CVE-2023-4251

Disclosure Date: October 31, 2023 (last updated November 09, 2023)
The EventPrime WordPress plugin before 3.2.0 does not have CSRF checks when creating bookings, which could allow attackers to make logged in users create unwanted bookings via CSRF attacks.
Attacker Value
Unknown

CVE-2023-4250

Disclosure Date: October 31, 2023 (last updated November 09, 2023)
The EventPrime WordPress plugin before 3.2.0 does not sanitise and escape some parameters before outputting them back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.
Attacker Value
Unknown

CVE-2023-45637

Disclosure Date: October 25, 2023 (last updated October 28, 2023)
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in EventPrime EventPrime – Events Calendar, Bookings and Tickets plugin <= 3.1.5 versions.
Attacker Value
Unknown

CVE-2023-3404

Disclosure Date: August 31, 2023 (last updated November 09, 2023)
The ProfileGrid plugin for WordPress is vulnerable to unauthorized decryption of private information in versions up to, and including, 5.5.0. This is due to the passphrase and iv being hardcoded in the 'pm_encrypt_decrypt_pass' function and used across all sites running the plugin. This makes it possible for authenticated attackers, with administrator-level permissions or above to decrypt and view users' passwords. If combined with another vulnerability, this can potentially grant lower-privileged users access to users' passwords.
Attacker Value
Unknown

CVE-2023-3714

Disclosure Date: July 18, 2023 (last updated October 08, 2023)
The ProfileGrid plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'edit_group' handler in versions up to, and including, 5.5.2. This makes it possible for authenticated attackers, with group ownership, to update group options, including the 'associate_role' parameter, which defines the member's role. This issue was partially patched in version 5.5.2 preventing privilege escalation, however, it was fully patched in 5.5.3.
Attacker Value
Unknown

CVE-2023-3713

Disclosure Date: July 18, 2023 (last updated November 09, 2023)
The ProfileGrid plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'profile_magic_check_smtp_connection' function in versions up to, and including, 5.5.1. This makes it possible for authenticated attackers, with subscriber-level permissions or above to update the site options arbitrarily. This can be used by attackers to achieve privilege escalation.
Attacker Value
Unknown

CVE-2023-3403

Disclosure Date: July 18, 2023 (last updated October 08, 2023)
The ProfileGrid plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'pm_upload_csv' function in versions up to, and including, 5.5.1. This makes it possible for authenticated attackers, with subscriber-level permissions or above to import new users and update existing users.
Attacker Value
Unknown

CVE-2022-38062

Disclosure Date: July 17, 2023 (last updated October 08, 2023)
Cross-Site Request Forgery (CSRF) vulnerability in Metagauss Download Theme plugin <= 1.0.9 versions.
Attacker Value
Unknown

CVE-2023-35884

Disclosure Date: June 20, 2023 (last updated October 08, 2023)
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in EventPrime plugin <= 3.0.5 versions.