Show filters
9 Total Results
Displaying 1-9 of 9
Sort by:
Attacker Value
Unknown

CVE-2022-4974

Disclosure Date: October 16, 2024 (last updated October 16, 2024)
The Freemius SDK, as used by hundreds of WordPress plugin and theme developers, was vulnerable to Cross-Site Request Forgery and Information disclosure due to missing capability checks and nonce protection on the _get_debug_log, _get_db_option, and the _set_db_option functions in versions up to, and including 2.4.2. Any WordPress plugin or theme running a version of Freemius less than 2.4.3 is vulnerable.
Attacker Value
Unknown

CVE-2022-1617

Disclosure Date: January 16, 2024 (last updated January 24, 2024)
The WP-Invoice WordPress plugin through 4.3.1 does not have CSRF check in place when updating its settings, and is lacking sanitisation as well as escaping in some of them, allowing attacker to make a logged in admin change them and add XSS payload in them
Attacker Value
Unknown

CVE-2020-25375

Disclosure Date: September 14, 2020 (last updated February 22, 2025)
Wordpress Plugin Store / SoftradeWeb SNC WP SMART CRM V1.8.7 is affected by: Cross Site Scripting via the Business Name field, Tax Code field, First Name field, Address field, Town field, Phone field, Mobile field, Place of Birth field, Web Site field, VAT Number field, Last Name field, Fax field, Email field, and Skype field.
Attacker Value
Unknown

CVE-2016-11008

Disclosure Date: September 20, 2019 (last updated November 27, 2024)
The wp-invoice plugin before 4.1.1 for WordPress has incorrect access control over wpi_paypal payer metadata updates.
Attacker Value
Unknown

CVE-2016-11010

Disclosure Date: September 20, 2019 (last updated November 27, 2024)
The wp-invoice plugin before 4.1.1 for WordPress has incorrect access control over wpi_twocheckout payer metadata updates.
Attacker Value
Unknown

CVE-2016-11009

Disclosure Date: September 20, 2019 (last updated November 27, 2024)
The wp-invoice plugin before 4.1.1 for WordPress has incorrect access control over wpi_interkassa payer metadata updates.
Attacker Value
Unknown

CVE-2016-11006

Disclosure Date: September 20, 2019 (last updated November 27, 2024)
The wp-invoice plugin before 4.1.1 for WordPress has incorrect access control for admin_init settings changes.
Attacker Value
Unknown

CVE-2016-11011

Disclosure Date: September 20, 2019 (last updated November 27, 2024)
The wp-invoice plugin before 4.1.1 for WordPress has wpi_update_user_option privilege escalation.
Attacker Value
Unknown

CVE-2016-11007

Disclosure Date: September 20, 2019 (last updated November 27, 2024)
The wp-invoice plugin before 4.1.1 for WordPress has incorrect access control over wpi_user_id for invoice retrieval.