Show filters
180 Total Results
Displaying 91-100 of 180
Sort by:
Attacker Value
Unknown

CVE-2022-1672

Disclosure Date: July 17, 2022 (last updated February 24, 2025)
The Insights from Google PageSpeed WordPress plugin before 4.0.7 does not verify for CSRF before doing various actions such as deleting Custom URLs, which could allow attackers to make a logged in admin perform such actions via CSRF attacks
Attacker Value
Unknown

CVE-2022-1990

Disclosure Date: June 27, 2022 (last updated February 24, 2025)
The Nested Pages WordPress plugin before 3.1.21 does not escape and sanitize the some of its settings, which could allow high privilege users to perform Stored Cross-Site Scripting attacks when the unfiltered_html is disallowed
Attacker Value
Unknown

CVE-2022-1977

Disclosure Date: June 27, 2022 (last updated February 24, 2025)
The Import Export All WordPress Images, Users & Post Types WordPress plugin before 6.5.3 does not fully validate the file to be imported via an URL before making an HTTP request to it, which could allow high privilege users such as admin to perform Blind SSRF attacks
Attacker Value
Unknown

CVE-2022-0431

Disclosure Date: April 04, 2022 (last updated February 23, 2025)
The Insights from Google PageSpeed WordPress plugin before 4.0.4 does not sanitise and escape various parameters before outputting them back in attributes in the plugin's settings dashboard, leading to Reflected Cross-Site Scripting
Attacker Value
Unknown

CVE-2022-24718

Disclosure Date: March 01, 2022 (last updated February 23, 2025)
ssr-pages is an HTML page builder for the purpose of server-side rendering (SSR). In versions prior to 0.1.4, a path traversal issue can occur when providing untrusted input to the `svg` property as an argument to the `build(MessagePageOptions)` function. While there is no known workaround at this time, there is a patch in version 0.1.4.
Attacker Value
Unknown

CVE-2022-24717

Disclosure Date: March 01, 2022 (last updated February 23, 2025)
ssr-pages is an HTML page builder for the purpose of server-side rendering (SSR). In versions prior to 0.1.5, a cross site scripting (XSS) issue can occur when providing untrusted input to the `redirect.link` property as an argument to the `build(MessagePageOptions)` function. While there is no known workaround at this time, there is a patch in version 0.1.5.
Attacker Value
Unknown

CVE-2022-0360

Disclosure Date: February 28, 2022 (last updated February 23, 2025)
The Easy Drag And drop All Import : WP Ultimate CSV Importer WordPress plugin before 6.4.3 does not sanitise and escaped imported comments, which could allow high privilege users to import malicious ones (either intentionnaly or not) and lead to Stored Cross-Site Scripting issues
Attacker Value
Unknown

CVE-2021-25106

Disclosure Date: February 07, 2022 (last updated February 23, 2025)
The Privacy Policy Generator, Terms & Conditions Generator WordPress Plugin : WPLegalPages WordPress plugin before 2.7.1 does not check for authorisation and has a flawed CSRF logic when saving its settings, allowing any authenticated users, such as subscriber, to update them. Furthermore, due to the lack of sanitisation and escaping, it could lead to Stored Cross-Site Scripting
Attacker Value
Unknown

CVE-2021-23209

Disclosure Date: December 15, 2021 (last updated February 23, 2025)
Multiple Authenticated (admin user role) Persistent Cross-Site Scripting (XSS) vulnerabilities discovered in AMP for WP – Accelerated Mobile Pages WordPress plugin (versions <= 1.0.77.32).
Attacker Value
Unknown

CVE-2021-23150

Disclosure Date: December 11, 2021 (last updated February 23, 2025)
Authenticated (admin+) Stored Cross-Site Scripting (XSS) vulnerability discovered in AMP for WP – Accelerated Mobile Pages plugin <= 1.0.77.31 versions.