Show filters
276 Total Results
Displaying 81-90 of 276
Sort by:
Attacker Value
Unknown

CVE-2022-40203

Disclosure Date: January 17, 2024 (last updated January 25, 2024)
Missing Authorization vulnerability in AlgolPlus Advanced Dynamic Pricing for WooCommerce.This issue affects Advanced Dynamic Pricing for WooCommerce: from n/a through 4.1.5.
Attacker Value
Unknown

CVE-2023-22674

Disclosure Date: December 21, 2023 (last updated December 29, 2023)
Missing Authorization, Cross-Site Request Forgery (CSRF) vulnerability in Hal Gatewood Dashicons + Custom Post Types.This issue affects Dashicons + Custom Post Types: from n/a through 1.0.2.
Attacker Value
Unknown

CVE-2023-27633

Disclosure Date: November 22, 2023 (last updated December 01, 2023)
Cross-Site Request Forgery (CSRF) vulnerability in Pixelgrade Customify – Intuitive Website Styling plugin <= 2.10.4 versions.
Attacker Value
Unknown

CVE-2023-48051

Disclosure Date: November 20, 2023 (last updated November 30, 2023)
An issue in /upydev/keygen.py in upydev v0.4.3 allows attackers to decrypt sensitive information via weak encryption padding.
Attacker Value
Unknown

CVE-2023-32298

Disclosure Date: November 08, 2023 (last updated November 16, 2023)
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Kathy Darling Simple User Listing plugin <= 1.9.2 versions.
Attacker Value
Unknown

CVE-2023-23702

Disclosure Date: November 06, 2023 (last updated November 15, 2023)
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Pixelgrade Comments Ratings plugin <= 1.1.7 versions.
Attacker Value
Unknown

CVE-2023-41685

Disclosure Date: November 06, 2023 (last updated November 10, 2023)
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in ilGhera Woocommerce Support System allows SQL Injection.This issue affects Woocommerce Support System: from n/a through 1.2.1.
Attacker Value
Unknown

CVE-2023-46595

Disclosure Date: November 02, 2023 (last updated February 15, 2024)
Net-NTLM leak via HTML injection in FireFlow VisualFlow workflow editor allows an attacker to obtain victim’s domain credentials and Net-NTLM hash which can lead to relay domain attacks. Fixed in A32.20 (b570 or above), A32.50 (b390 or above)
Attacker Value
Unknown

CVE-2023-5745

Disclosure Date: October 25, 2023 (last updated November 03, 2023)
The Reusable Text Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'text-blocks' shortcode in versions up to, and including, 1.5.3 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with author-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Attacker Value
Unknown

CVE-2023-45655

Disclosure Date: October 16, 2023 (last updated October 20, 2023)
Cross-Site Request Forgery (CSRF) vulnerability in PixelGrade PixFields plugin <= 0.7.0 versions.