Show filters
140 Total Results
Displaying 71-80 of 140
Sort by:
Attacker Value
Unknown
CVE-2023-0424
Disclosure Date: April 24, 2023 (last updated October 08, 2023)
The MS-Reviews WordPress plugin through 1.5 does not sanitise and escape reviews, which could allow users any authenticated users, such as Subscribers to perform Stored Cross-Site Scripting attacks
0
Attacker Value
Unknown
CVE-2022-44580
Disclosure Date: March 15, 2023 (last updated February 24, 2025)
SQL Injection (SQLi) vulnerability in RichPlugins Plugin for Google Reviews plugin <= 2.2.3 versions.
0
Attacker Value
Unknown
CVE-2023-25206
Disclosure Date: March 14, 2023 (last updated February 24, 2025)
PrestaShop ws_productreviews < 3.6.2 is vulnerable to SQL Injection.
0
Attacker Value
Unknown
CVE-2022-4761
Disclosure Date: February 21, 2023 (last updated October 08, 2023)
The Post Views Count WordPress plugin through 3.0.2 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks
0
Attacker Value
Unknown
CVE-2023-0080
Disclosure Date: February 13, 2023 (last updated October 08, 2023)
The Customer Reviews for WooCommerce WordPress plugin before 5.16.0 does not validate one of its shortcode attribute, which could allow users with a contributor role and above to include arbitrary files via a traversal attack. This could also allow them to read non PHP files and retrieve their content. RCE could also be achieved if the attacker manage to upload a malicious image containing PHP code, and then include it via the affected attribute, on a default WP install, authors could easily achieve that given that they have the upload_file capability.
0
Attacker Value
Unknown
CVE-2023-0061
Disclosure Date: February 13, 2023 (last updated October 08, 2023)
The Judge.me Product Reviews for WooCommerce WordPress plugin before 1.3.21 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.
0
Attacker Value
Unknown
CVE-2022-4470
Disclosure Date: January 30, 2023 (last updated October 08, 2023)
The Widgets for Google Reviews WordPress plugin before 9.8 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as admins.
0
Attacker Value
Unknown
CVE-2022-45369
Disclosure Date: November 18, 2022 (last updated February 24, 2025)
Auth. (subscriber+) Broken Access Control vulnerability in Plugin for Google Reviews plugin <= 2.2.2 on WordPress.
0
Attacker Value
Unknown
CVE-2022-38134
Disclosure Date: September 22, 2022 (last updated February 24, 2025)
Authenticated (subscriber+) Broken Access Control vulnerability in Customer Reviews for WooCommerce plugin <= 5.3.5 at WordPress.
0
Attacker Value
Unknown
CVE-2022-38470
Disclosure Date: September 22, 2022 (last updated February 24, 2025)
Cross-Site Request Forgery (CSRF) vulnerability in Customer Reviews for WooCommerce plugin <= 5.3.5 at WordPress.
0