Show filters
140 Total Results
Displaying 81-90 of 140
Sort by:
Attacker Value
Unknown
CVE-2022-40194
Disclosure Date: September 22, 2022 (last updated February 24, 2025)
Unauthenticated Sensitive Information Disclosure vulnerability in Customer Reviews for WooCommerce plugin <= 5.3.5 at WordPress
0
Attacker Value
Unknown
CVE-2022-2555
Disclosure Date: August 22, 2022 (last updated February 24, 2025)
The Yotpo Reviews for WooCommerce WordPress plugin through 2.0.4 lacks nonce check when updating its settings, which could allow attacker to make a logged in admin change them via a CSRF attack.
0
Attacker Value
Unknown
CVE-2022-2108
Disclosure Date: July 18, 2022 (last updated February 24, 2025)
The plugin Wbcom Designs – BuddyPress Group Reviews for WordPress is vulnerable to unauthorized settings changes and review modification due to missing capability checks and improper nonce checks in several functions related to said actions in versions up to, and including, 2.8.3. This makes it possible for unauthenticated attackers to modify reviews and plugin settings on the affected site.
0
Attacker Value
Unknown
CVE-2022-1772
Disclosure Date: June 13, 2022 (last updated February 23, 2025)
The Google Places Reviews WordPress plugin before 2.0.0 does not properly escape its Google API key setting, which is reflected on the site's administration panel. A malicious administrator could abuse this bug, in a multisite WordPress configuration, to trick super-administrators into viewing the booby-trapped payload and taking over their account.
0
Attacker Value
Unknown
CVE-2021-24867
Disclosure Date: February 21, 2022 (last updated February 23, 2025)
Numerous Plugins and Themes from the AccessPress Themes (aka Access Keys) vendor are backdoored due to their website being compromised. Only plugins and themes downloaded via the vendor website are affected, and those hosted on wordpress.org are not. However, all of them were updated or removed to avoid any confusion
0
Attacker Value
Unknown
CVE-2022-25203
Disclosure Date: February 15, 2022 (last updated February 23, 2025)
Jenkins Team Views Plugin 0.9.0 and earlier does not escape team names, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Overall/Read permission.
0
Attacker Value
Unknown
CVE-2022-23979
Disclosure Date: January 06, 2022 (last updated February 23, 2025)
Authenticated (admin+) Stored Cross-Site Scripting (XSS) vulnerability discovered in Ultimate Reviews WordPress plugin (versions <= 3.0.15).
0
Attacker Value
Unknown
CVE-2021-24973
Disclosure Date: January 03, 2022 (last updated February 23, 2025)
The Site Reviews WordPress plugin before 5.17.3 does not sanitise and escape the site-reviews parameter of the glsr_action AJAX action (available to unauthenticated and any authenticated users), allowing them to perform Cross-Site Scripting attacks against logged in admins viewing the Tool dashboard of the plugin
0
Attacker Value
Unknown
CVE-2021-24894
Disclosure Date: November 23, 2021 (last updated February 23, 2025)
The Reviews Plus WordPress plugin before 1.2.14 does not validate the submitted rating, allowing submission of long integer, causing a Denial of Service in the review section when an authenticated user submit such rating and the reviews are set to be displayed on the post/page
0
Attacker Value
Unknown
CVE-2021-24613
Disclosure Date: September 20, 2021 (last updated February 23, 2025)
The Post Views Counter WordPress plugin before 1.3.5 does not sanitise or escape its Post Views Label settings, which could allow high privilege users to perform Cross-Site Scripting attacks in the frontend even when the unfiltered_html capability is disallowed
0