Show filters
140 Total Results
Displaying 71-80 of 140
Sort by:
Attacker Value
Unknown

CVE-2023-0424

Disclosure Date: April 24, 2023 (last updated October 08, 2023)
The MS-Reviews WordPress plugin through 1.5 does not sanitise and escape reviews, which could allow users any authenticated users, such as Subscribers to perform Stored Cross-Site Scripting attacks
Attacker Value
Unknown

CVE-2022-44580

Disclosure Date: March 15, 2023 (last updated February 24, 2025)
SQL Injection (SQLi) vulnerability in RichPlugins Plugin for Google Reviews plugin <= 2.2.3 versions.
Attacker Value
Unknown

CVE-2023-25206

Disclosure Date: March 14, 2023 (last updated February 24, 2025)
PrestaShop ws_productreviews < 3.6.2 is vulnerable to SQL Injection.
Attacker Value
Unknown

CVE-2022-4761

Disclosure Date: February 21, 2023 (last updated October 08, 2023)
The Post Views Count WordPress plugin through 3.0.2 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks
Attacker Value
Unknown

CVE-2023-0080

Disclosure Date: February 13, 2023 (last updated October 08, 2023)
The Customer Reviews for WooCommerce WordPress plugin before 5.16.0 does not validate one of its shortcode attribute, which could allow users with a contributor role and above to include arbitrary files via a traversal attack. This could also allow them to read non PHP files and retrieve their content. RCE could also be achieved if the attacker manage to upload a malicious image containing PHP code, and then include it via the affected attribute, on a default WP install, authors could easily achieve that given that they have the upload_file capability.
Attacker Value
Unknown

CVE-2023-0061

Disclosure Date: February 13, 2023 (last updated October 08, 2023)
The Judge.me Product Reviews for WooCommerce WordPress plugin before 1.3.21 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.
Attacker Value
Unknown

CVE-2022-4470

Disclosure Date: January 30, 2023 (last updated October 08, 2023)
The Widgets for Google Reviews WordPress plugin before 9.8 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as admins.
Attacker Value
Unknown

CVE-2022-45369

Disclosure Date: November 18, 2022 (last updated February 24, 2025)
Auth. (subscriber+) Broken Access Control vulnerability in Plugin for Google Reviews plugin <= 2.2.2 on WordPress.
Attacker Value
Unknown

CVE-2022-38134

Disclosure Date: September 22, 2022 (last updated February 24, 2025)
Authenticated (subscriber+) Broken Access Control vulnerability in Customer Reviews for WooCommerce plugin <= 5.3.5 at WordPress.
Attacker Value
Unknown

CVE-2022-38470

Disclosure Date: September 22, 2022 (last updated February 24, 2025)
Cross-Site Request Forgery (CSRF) vulnerability in Customer Reviews for WooCommerce plugin <= 5.3.5 at WordPress.