Show filters
4 Total Results
Displaying 1-4 of 4
Sort by:
Attacker Value
Unknown
CVE-2024-0910
Disclosure Date: June 06, 2024 (last updated July 26, 2024)
The Restrict for Elementor plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.0.6 due to improper restrictions on hidden data that make it accessible through the REST API. This makes it possible for unauthenticated attackers to extract potentially sensitive data from post content.
0
Attacker Value
Unknown
CVE-2021-34625
Disclosure Date: July 02, 2021 (last updated November 28, 2024)
A vulnerability in the saveCustomType function of the WP Upload Restriction WordPress plugin allows low-level authenticated users to inject arbitrary web scripts. This issue affects versions 2.2.3 and prior.
0
Attacker Value
Unknown
CVE-2021-34627
Disclosure Date: July 02, 2021 (last updated November 28, 2024)
A vulnerability in the getSelectedMimeTypesByRole function of the WP Upload Restriction WordPress plugin allows low-level authenticated users to view custom extensions added by administrators. This issue affects versions 2.2.3 and prior.
0
Attacker Value
Unknown
CVE-2021-34626
Disclosure Date: July 02, 2021 (last updated November 28, 2024)
A vulnerability in the deleteCustomType function of the WP Upload Restriction WordPress plugin allows low-level authenticated users to delete custom extensions added by administrators. This issue affects versions 2.2.3 and prior.
0