Show filters
9 Total Results
Displaying 1-9 of 9
Sort by:
Attacker Value
Unknown

CVE-2025-22722

Disclosure Date: January 21, 2025 (last updated February 27, 2025)
Missing Authorization vulnerability in Widget Options Team Widget Options allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Widget Options: from n/a through 4.0.8.
0
Attacker Value
Unknown

CVE-2024-12507

Disclosure Date: December 24, 2024 (last updated February 27, 2025)
The Optio Dentistry plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'optio-lightbox' shortcode in all versions up to, and including, 2.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Attacker Value
Unknown

CVE-2020-36219

Disclosure Date: January 26, 2021 (last updated November 28, 2024)
An issue was discovered in the atomic-option crate through 2020-10-31 for Rust. Because AtomicOption<T> implements Sync unconditionally, a data race can occur.
Attacker Value
Unknown

CVE-2019-15319

Disclosure Date: August 22, 2019 (last updated November 27, 2024)
The option-tree plugin before 2.7.0 for WordPress has Object Injection by leveraging a valid nonce.
0
Attacker Value
Unknown

CVE-2019-15320

Disclosure Date: August 22, 2019 (last updated November 27, 2024)
The option-tree plugin before 2.7.3 for WordPress has Object Injection because the + character is mishandled.
0
Attacker Value
Unknown

CVE-2019-15321

Disclosure Date: August 22, 2019 (last updated November 27, 2024)
The option-tree plugin before 2.7.3 for WordPress has Object Injection because serialized classes are mishandled.
0
Attacker Value
Unknown

CVE-2016-10895

Disclosure Date: August 20, 2019 (last updated November 27, 2024)
The option-tree plugin before 2.6.0 for WordPress has XSS via an add_list_item or add_social_links AJAX request.
0
Attacker Value
Unknown

CVE-2015-9320

Disclosure Date: August 20, 2019 (last updated November 27, 2024)
The option-tree plugin before 2.5.4 for WordPress has XSS related to add_query_arg.
Attacker Value
Unknown

CVE-2018-3752

Disclosure Date: July 03, 2018 (last updated November 27, 2024)
The utilities function in all versions <= 1.0.0 of the merge-options node module can be tricked into modifying the prototype of Object when the attacker can control part of the structure passed to this function. This can let an attacker add or modify existing properties that will exist on all objects.
0