Filtered by vendor Wpchill Subscriptions
Total 26 CVE
CVE Vendors Products Updated CVSS v3.1
CVE-2022-1054 1 Wpchill 1 Rsvp And Event Management 2024-08-02 5.3 Medium
The RSVP and Event Management Plugin WordPress plugin before 2.7.8 does not have any authorisation checks when exporting its entries, and has the export function hooked to the init action. As a result, unauthenticated attackers could call it and retrieve PII such as first name, last name and email address of user registered for events
CVE-2023-34007 1 Wpchill 1 Download Monitor 2024-08-02 9.9 Critical
Unrestricted Upload of File with Dangerous Type vulnerability in WPChill Download Monitor.This issue affects Download Monitor: from n/a through 4.8.3.
CVE-2023-26013 1 Wpchill 1 Strong Testimonials 2024-08-02 6.5 Medium
Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in WPChill Strong Testimonials plugin <= 3.0.2 versions.
CVE-2023-28171 1 Wpchill 1 Brilliance 2024-08-02 5.4 Medium
Auth. (subscriber+) Stored Cross-Site Scripting (XSS) vulnerability in WP Chill Brilliance theme <= 1.3.1 versions.
CVE-2023-25451 1 Wpchill 1 Cpo Content Types 2024-08-02 5.9 Medium
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in WPChill CPO Content Types plugin <= 1.1.0 versions.
CVE-2023-5704 1 Wpchill 1 Cpo Shortcodes 2024-08-02 6.4 Medium
The CPO Shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcodes in all versions up to, and including, 1.5.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.