Search Results (20818 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2022-2532 1 Slickremix 1 Feed Them Social 2024-11-21 6.1 Medium
The Feed Them Social WordPress plugin before 3.0.1 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting
CVE-2022-2448 1 Resmush.it 1 Resmush.it Image Optimizer 2024-11-21 4.8 Medium
The reSmush.it WordPress plugin before 0.4.6 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when unfiltered_html is disallowed.
CVE-2022-2426 1 Thinkific 1 Thinkific Uploader 2024-11-21 4.8 Medium
The Thinkific Uploader WordPress plugin through 1.0.0 does not sanitise and escape its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks against other administrators.
CVE-2022-2425 1 Wp Ds Blog Map Project 1 Wp Ds Blog Map 2024-11-21 4.8 Medium
The WP DS Blog Map WordPress plugin through 3.1.3 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks when the unfiltered_html capability is disallowed (for example in multisite setup)
CVE-2022-2424 1 Google Maps Anywhere Project 1 Google Maps Anywhere 2024-11-21 4.8 Medium
The Google Maps Anywhere WordPress plugin through 1.2.6.3 does not sanitise and escape any of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks when the unfiltered_html capability is disallowed (for example in multisite setup)
CVE-2022-2423 1 Designwall 1 Dw Promobar 2024-11-21 4.8 Medium
The DW Promobar WordPress plugin through 1.0.4 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks when the unfiltered_html capability is disallowed (for example in multisite setup)
CVE-2022-2412 1 Better Tag Cloud Project 1 Better Tag Cloud 2024-11-21 4.8 Medium
The Better Tag Cloud WordPress plugin through 0.99.5 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks when the unfiltered_html capability is disallowed (for example in multisite setup)
CVE-2022-2411 1 Auto More Tag Project 1 Auto More Tag 2024-11-21 4.8 Medium
The Auto More Tag WordPress plugin through 4.0.0 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks when the unfiltered_html capability is disallowed (for example in multisite setup)
CVE-2022-2410 1 Mtouch Quiz Project 1 Mtouch Quiz 2024-11-21 4.8 Medium
The mTouch Quiz WordPress plugin through 3.1.3 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks when the unfiltered_html capability is disallowed (for example in multisite setup)
CVE-2022-2409 1 Rough Chart Project 1 Rough Chart 2024-11-21 4.8 Medium
The Rough Chart WordPress plugin through 1.0.0 does not properly escape chart data label, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.
CVE-2022-2407 1 Puvox 1 Wp Phpmyadmin 2024-11-21 4.8 Medium
The WP phpMyAdmin WordPress plugin before 5.2.0.4 does not escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks when the unfiltered_html capability is disallowed (for example in multisite setup)
CVE-2022-2398 1 Najeebmedia 1 Wordpress Comments Fields 2024-11-21 4.8 Medium
The WordPress Comments Fields WordPress plugin before 4.1 does not escape Field Error Message, which could allow high-privileged users to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed
CVE-2022-2395 1 Weformspro 1 Weforms 2024-11-21 4.8 Medium
The weForms WordPress plugin before 1.6.14 does not sanitise and escape its settings, allowing high privilege users such as admin to perform cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.
CVE-2022-2392 1 Lana 1 Lana Downloads Manager 2024-11-21 6.5 Medium
The Lana Downloads Manager WordPress plugin before 1.8.0 is affected by an arbitrary file download vulnerability that can be exploited by users with "Contributor" permissions or higher.
CVE-2022-2391 1 Wpzoom 1 Inspiro Pro 2024-11-21 5.4 Medium
The Inspiro PRO WordPress plugin does not sanitize the portfolio slider description, allowing users with privileges as low as Contributor to inject JavaScript into the description.
CVE-2022-2389 1 Funnelkit 1 Funnelkit Automations 2024-11-21 4.3 Medium
The Abandoned Cart Recovery for WooCommerce, Follow Up Emails, Newsletter Builder & Marketing Automation By Autonami WordPress plugin before 2.1.2 does not have authorisation and CSRF checks in one of its AJAX action, allowing any authenticated users, such as subscriber to create automations
CVE-2022-2388 1 Wow-company 1 Wp Coder 2024-11-21 6.5 Medium
The WP Coder WordPress plugin before 2.5.3 does not have CSRF check in place when deleting code created by the plugin, which could allow attackers to make a logged in admin delete arbitrary ones via a CSRF attack
CVE-2022-2386 1 Automattic 1 Crowdsignal Dashboard 2024-11-21 6.1 Medium
The Crowdsignal Dashboard WordPress plugin before 3.0.8 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting
CVE-2022-2384 1 Supsystic 1 Digital Publications By Supsystic 2024-11-21 4.8 Medium
The Digital Publications by Supsystic WordPress plugin before 1.7.4 does not sanitise and escape its settings, allowing high privilege users such as admin to perform cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.
CVE-2022-2383 1 Slickremix 1 Feed Them Social 2024-11-21 6.1 Medium
The Feed Them Social WordPress plugin before 3.0.1 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting