Search Results (20777 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2022-4836 1 Pickplugins 1 Breadcrumb 2025-03-25 5.4 Medium
The Breadcrumb WordPress plugin before 1.5.33 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as admins.
CVE-2022-4826 1 Simple Tooltips Project 1 Simple Tooltips 2025-03-25 5.4 Medium
The Simple Tooltips WordPress plugin before 2.1.4 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks
CVE-2022-4626 1 Passwordprotectwp 1 Password Protect Wordpress 2025-03-25 5.4 Medium
The PPWP WordPress plugin before 1.8.6 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as admins.
CVE-2022-4489 1 Pluginus 1 Husky - Products Filter Professional For Woocommerce 2025-03-25 7.2 High
The HUSKY WordPress plugin before 1.3.2 unserializes user input provided via the settings, which could allow high privilege users such as admin to perform PHP Object Injection when a suitable gadget is present.
CVE-2024-4860 1 Rebelcode 1 Rss Aggregator 2025-03-25 5.4 Medium
The 'WordPress RSS Aggregator' WordPress Plugin, versions < 4.23.9 are affected by a Cross-Site Scripting (XSS) vulnerability due to the lack of sanitization of the  'notice_id'  GET parameter.
CVE-2024-3552 1 Salephpscripts 1 Web Directory Free 2025-03-25 9.8 Critical
The Web Directory Free WordPress plugin before 1.7.0 does not sanitise and escape a parameter before using it in a SQL statement via an AJAX action available to unauthenticated users, leading to a SQL injection with different techniques like UNION, Time-Based and Error-Based.
CVE-2024-3474 1 Wow-company 1 Wow Skype Buttons 2025-03-25 8.8 High
The Wow Skype Buttons WordPress plugin before 4.0.4 does not have CSRF checks in some bulk actions, which could allow attackers to make logged in admins perform unwanted actions, such as deleting buttons via CSRF attacks
CVE-2022-2094 1 Yellowyard 1 Yellow Yard Searchbar 2025-03-25 6.1 Medium
The Yellow Yard Searchbar WordPress plugin before 2.8.2 does not escape some URL parameters before outputting them back to the user, leading to Reflected Cross-Site Scripting
CVE-2023-5355 1 Getawesomesupport 1 Awesome Support 2025-03-24 8.1 High
The Awesome Support WordPress plugin before 6.1.5 does not sanitize file paths when deleting temporary attachment files, allowing a ticket submitter to delete arbitrary files on the server.
CVE-2019-15839 1 Sinaextra 1 Sina Extension For Elementor 2025-03-24 N/A
The sina-extension-for-elementor plugin before 2.2.1 for WordPress has local file inclusion.
CVE-2024-1589 1 Pressified 1 Sendpress 2025-03-24 6.1 Medium
The SendPress Newsletters WordPress plugin through 1.23.11.6 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)
CVE-2024-4270 1 Andibauer 1 Svgmagic 2025-03-24 5.4 Medium
The SVGMagic WordPress plugin through 1.1 does not sanitize SVG file contents, which enables users with at least the author role to SVG with malicious JavaScript to conduct Stored XSS attacks.
CVE-2021-24177 1 Filemanagerpro 1 File Manager 2025-03-24 5.4 Medium
In the default configuration of the File Manager WordPress plugin before 7.1, a Reflected XSS can occur on the endpoint /wp-admin/admin.php?page=wp_file_manager_properties when a payload is submitted on the User-Agent parameter. The payload is then reflected back on the web application response.
CVE-2023-0405 1 Gptaipower 1 Gpt Ai Power 2025-03-21 5.4 Medium
The GPT AI Power: Content Writer & ChatGPT & Image Generator & WooCommerce Product Writer & AI Training WordPress plugin before 1.4.38 does not perform any kind of nonce or privilege checks before letting logged-in users modify arbitrary posts.
CVE-2023-0262 1 Ljapps 1 Wp Airbnb Review Slider 2025-03-21 7.7 High
The WP Airbnb Review Slider WordPress plugin before 3.3 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by users with a role as low as subscriber.
CVE-2023-0098 1 Getlasso 1 Simple Urls 2025-03-21 7.7 High
The Simple URLs WordPress plugin before 115 does not escape some parameters before using them in various SQL statements used by AJAX actions available by any authenticated users, leading to a SQL injection exploitable by low privilege users such as subscriber.
CVE-2023-0075 1 Amazonjs Project 1 Amazonjs 2025-03-21 6.8 Medium
The Amazon JS WordPress plugin through 0.10 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.
CVE-2023-0061 1 Judge 1 Product Reviews For Woocommerce 2025-03-21 6.8 Medium
The Judge.me Product Reviews for WooCommerce WordPress plugin before 1.3.21 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.
CVE-2022-4512 1 Better Font Awesome Project 1 Better Font Awesome 2025-03-21 6.8 Medium
The Better Font Awesome WordPress plugin before 2.0.4 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.
CVE-2022-4488 1 Widgets On Pages Project 1 Widgets On Pages 2025-03-21 6.8 Medium
The Widgets on Pages WordPress plugin before 1.8.0 does not validate and escape its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as admins.