Show filters
140 Total Results
Displaying 81-90 of 140
Sort by:
Attacker Value
Unknown

CVE-2022-40194

Disclosure Date: September 22, 2022 (last updated February 24, 2025)
Unauthenticated Sensitive Information Disclosure vulnerability in Customer Reviews for WooCommerce plugin <= 5.3.5 at WordPress
Attacker Value
Unknown

CVE-2022-2555

Disclosure Date: August 22, 2022 (last updated February 24, 2025)
The Yotpo Reviews for WooCommerce WordPress plugin through 2.0.4 lacks nonce check when updating its settings, which could allow attacker to make a logged in admin change them via a CSRF attack.
Attacker Value
Unknown

CVE-2022-2108

Disclosure Date: July 18, 2022 (last updated February 24, 2025)
The plugin Wbcom Designs – BuddyPress Group Reviews for WordPress is vulnerable to unauthorized settings changes and review modification due to missing capability checks and improper nonce checks in several functions related to said actions in versions up to, and including, 2.8.3. This makes it possible for unauthenticated attackers to modify reviews and plugin settings on the affected site.
Attacker Value
Unknown

CVE-2022-1772

Disclosure Date: June 13, 2022 (last updated February 23, 2025)
The Google Places Reviews WordPress plugin before 2.0.0 does not properly escape its Google API key setting, which is reflected on the site's administration panel. A malicious administrator could abuse this bug, in a multisite WordPress configuration, to trick super-administrators into viewing the booby-trapped payload and taking over their account.
Attacker Value
Unknown

CVE-2021-24867

Disclosure Date: February 21, 2022 (last updated February 23, 2025)
Numerous Plugins and Themes from the AccessPress Themes (aka Access Keys) vendor are backdoored due to their website being compromised. Only plugins and themes downloaded via the vendor website are affected, and those hosted on wordpress.org are not. However, all of them were updated or removed to avoid any confusion
Attacker Value
Unknown

CVE-2022-25203

Disclosure Date: February 15, 2022 (last updated February 23, 2025)
Jenkins Team Views Plugin 0.9.0 and earlier does not escape team names, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Overall/Read permission.
Attacker Value
Unknown

CVE-2022-23979

Disclosure Date: January 06, 2022 (last updated February 23, 2025)
Authenticated (admin+) Stored Cross-Site Scripting (XSS) vulnerability discovered in Ultimate Reviews WordPress plugin (versions <= 3.0.15).
Attacker Value
Unknown

CVE-2021-24973

Disclosure Date: January 03, 2022 (last updated February 23, 2025)
The Site Reviews WordPress plugin before 5.17.3 does not sanitise and escape the site-reviews parameter of the glsr_action AJAX action (available to unauthenticated and any authenticated users), allowing them to perform Cross-Site Scripting attacks against logged in admins viewing the Tool dashboard of the plugin
Attacker Value
Unknown

CVE-2021-24894

Disclosure Date: November 23, 2021 (last updated February 23, 2025)
The Reviews Plus WordPress plugin before 1.2.14 does not validate the submitted rating, allowing submission of long integer, causing a Denial of Service in the review section when an authenticated user submit such rating and the reviews are set to be displayed on the post/page
Attacker Value
Unknown

CVE-2021-24613

Disclosure Date: September 20, 2021 (last updated February 23, 2025)
The Post Views Counter WordPress plugin before 1.3.5 does not sanitise or escape its Post Views Label settings, which could allow high privilege users to perform Cross-Site Scripting attacks in the frontend even when the unfiltered_html capability is disallowed