Search Results (20883 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2022-1644 1 Call\&book Mobile Bar Project 1 Call\&book Mobile Bar 2024-11-21 4.8 Medium
The Call&Book Mobile Bar WordPress plugin through 1.2.2 does not sanitize and escape some of its settings, which could allow high privilege users such as admin to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed.
CVE-2022-1643 1 Birthdays Widget Project 1 Birthdays Widget 2024-11-21 4.8 Medium
The Birthdays Widget WordPress plugin through 1.7.18 does not sanitise and escape some of its fields, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks when the unfiltered_html capability is disallowed
CVE-2022-1630 1 Wp-email Project 1 Wp-email 2024-11-21 6.5 Medium
The WP-EMail WordPress plugin before 2.69.0 does not protect its log deletion functionality with nonce checks, allowing attacker to make a logged in admin delete logs via a CSRF attack
CVE-2022-1627 1 Zatzlabs 1 My Private Site 2024-11-21 4.3 Medium
The My Private Site WordPress plugin before 3.0.8 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack
CVE-2022-1626 1 Sharebar Project 1 Sharebar 2024-11-21 5.4 Medium
The Sharebar WordPress plugin through 1.4.1 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack and also lead to Stored Cross-Site Scripting issue due to the lack of sanitisation and escaping in some of them
CVE-2022-1625 1 Wpexperts 1 New User Approve 2024-11-21 4.3 Medium
The New User Approve WordPress plugin before 2.4 does not have CSRF check in place when updating its settings and adding invitation codes, which could allow attackers to add invitation codes (for bypassing the provided restrictions) and to change plugin settings by tricking admin users into visiting specially crafted websites.
CVE-2022-1624 1 Latest Tweets Widget Project 1 Latest Tweets Widget 2024-11-21 6.5 Medium
The Latest Tweets Widget WordPress plugin through 1.1.4 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack
CVE-2022-1618 1 Marcorulicke 1 Coru Lfmember 2024-11-21 6.1 Medium
The Coru LFMember WordPress plugin through 1.0.2 does not have CSRF check in place when adding a new game, and is lacking sanitisation as well as escaping in their settings, allowing attacker to make a logged in admin add an arbitrary game with XSS payloads
CVE-2022-1614 1 Wp-email Project 1 Wp-email 2024-11-21 7.5 High
The WP-EMail WordPress plugin before 2.69.0 prioritizes getting a visitor's IP from certain HTTP headers over PHP's REMOTE_ADDR, which makes it possible to bypass IP-based anti-spamming restrictions.
CVE-2022-1612 1 Webriti 1 Webriti Smtp Mail 2024-11-21 6.5 Medium
The Webriti SMTP Mail WordPress plugin through 1.0 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack
CVE-2022-1611 1 Bulk Page Creator Project 1 Bulk Page Creator 2024-11-21 8.8 High
The Bulk Page Creator WordPress plugin before 1.1.4 does not protect its page creation functionalities with nonce checks, which makes them vulnerable to CSRF.
CVE-2022-1610 1 Seamless Donations Project 1 Seamless Donations 2024-11-21 6.5 Medium
The Seamless Donations WordPress plugin before 5.1.9 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack
CVE-2022-1608 1 Byonepress 1 Social Locker 2024-11-21 6.5 Medium
The OnePress Social Locker WordPress plugin through 5.6.2 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack
CVE-2022-1605 1 Email Users Project 1 Email Users 2024-11-21 6.5 Medium
The Email Users WordPress plugin through 4.8.8 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack and change the notification settings of arbitrary users
CVE-2022-1604 1 Mailerlite 1 Mailerlite Signup Forms 2024-11-21 6.1 Medium
The MailerLite WordPress plugin before 1.5.4 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting
CVE-2022-1603 1 Webfwd 1 Mail Subscribe List 2024-11-21 4.3 Medium
The Mail Subscribe List WordPress plugin before 2.1.4 does not have CSRF check in place when deleting subscribed users, which could allow attackers to make a logged in admin perform such action and delete arbitrary users from the subscribed list
CVE-2022-1601 1 Alexanderschneider 1 User Access Manager 2024-11-21 5.3 Medium
The User Access Manager WordPress plugin before 2.2.18 prioritizes getting a visitor's IP from certain HTTP headers over PHP's REMOTE_ADDR, which makes it possible for attackers to access restricted content in certain situations.
CVE-2022-1600 1 Yop-poll 1 Yop Poll 2024-11-21 5.3 Medium
The YOP Poll WordPress plugin before 6.4.3 prioritizes getting a visitor's IP from certain HTTP headers over PHP's REMOTE_ADDR, which makes it possible to bypass IP-based limitations to vote in certain situations.
CVE-2022-1599 1 Admin Management Xtended Project 1 Admin Management Xtended 2024-11-21 6.5 Medium
The Admin Management Xtended WordPress plugin before 2.4.5 does not have CSRF checks in some of its AJAX actions, allowing attackers to make a logged users with the right capabilities to call them. This can lead to changes in post status (draft, published), slug, post date, comment status (enabled, disabled) and more.
CVE-2022-1598 1 2code 1 Wpqa Builder 2024-11-21 5.3 Medium
The WPQA Builder WordPress plugin before 5.5 which is a companion to the Discy and Himer , lacks authentication in a REST API endpoint, allowing unauthenticated users to discover private questions sent between users on the site.