Show filters
123 Total Results
Displaying 81-90 of 123
Sort by:
Attacker Value
Unknown

CVE-2023-30777

Disclosure Date: May 10, 2023 (last updated October 08, 2023)
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in WP Engine Advanced Custom Fields Pro, WP Engine Advanced Custom Fields plugins <= 6.1.5 versions.
Attacker Value
Unknown

CVE-2022-46864

Disclosure Date: May 09, 2023 (last updated October 08, 2023)
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Umair Saleem Woocommerce Custom Checkout Fields Editor With Drag & Drop plugin <= 0.1 versions.
Attacker Value
Unknown

CVE-2022-46844

Disclosure Date: May 09, 2023 (last updated October 08, 2023)
Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in PixelGrade PixFields plugin <= 0.7.0 versions.
Attacker Value
Unknown

CVE-2023-1196

Disclosure Date: May 02, 2023 (last updated October 08, 2023)
The Advanced Custom Fields (ACF) Free and Pro WordPress plugins 6.x before 6.1.0 and 5.x before 5.12.5 unserialize user controllable data, which could allow users with a role of Contributor and above to perform PHP Object Injection when a suitable gadget is present.
Attacker Value
Unknown

CVE-2023-0277

Disclosure Date: April 17, 2023 (last updated October 08, 2023)
The WC Fields Factory WordPress plugin through 4.1.5 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by high privilege users such as admin
Attacker Value
Unknown

CVE-2023-28855

Disclosure Date: April 05, 2023 (last updated October 08, 2023)
Fields is a GLPI plugin that allows users to add custom fields on GLPI items forms. Prior to versions 1.13.1 and 1.20.4, lack of access control check allows any authenticated user to write data to any fields container, including those to which they have no configured access. Versions 1.13.1 and 1.20.4 contain a patch for this issue.
Attacker Value
Unknown

CVE-2022-4831

Disclosure Date: January 30, 2023 (last updated October 08, 2023)
The Custom User Profile Fields for User Registration WordPress plugin before 1.8.1 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as admins.
Attacker Value
Unknown

CVE-2022-4442

Disclosure Date: January 16, 2023 (last updated October 08, 2023)
The Custom Post Types and Custom Fields creator WordPress plugin before 2.3.3 does not sanitize and escape some of its settings, which could allow high-privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example, in multisite setup).
Attacker Value
Unknown

CVE-2022-4117

Disclosure Date: December 26, 2022 (last updated October 08, 2023)
The IWS WordPress plugin through 1.0 does not properly escape a parameter before using it in a SQL statement via an AJAX action available to unauthenticated users, leading to an unauthenticated SQL injection.
Attacker Value
Unknown

CVE-2022-40841

Disclosure Date: December 21, 2022 (last updated February 24, 2025)
A cross-site scripting (XSS) vulnerability in NdkAdvancedCustomizationFields v3.5.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payloads injected into the "htmlNodes" parameter.