Search
Search Results (42 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2022-4395 | 1 Wpswings | 1 Membership For Woocommerce | 2025-03-27 | 9.8 Critical |
| The Membership For WooCommerce WordPress plugin before 2.1.7 does not validate uploaded files, which could allow unauthenticated users to upload arbitrary files, such as malicious PHP code, and achieve RCE. | ||||
| CVE-2022-4321 | 1 Wpswings | 1 Pdf Generator For Wordpress | 2025-03-26 | 6.1 Medium |
| The PDF Generator for WordPress plugin before 1.1.2 includes a vendored dompdf example file which is susceptible to Reflected Cross-Site Scripting and could be used against high privilege users such as admin | ||||