Filtered by vendor Otwthemes Subscriptions
Filtered by product Buttons Shortcode And Widget Subscriptions
Total 2 CVE
CVE Vendors Products Updated CVSS v3.1
CVE-2024-0711 1 Otwthemes 1 Buttons Shortcode And Widget 2024-10-27 6.1 Medium
The Buttons Shortcode and Widget WordPress plugin through 1.16 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.
CVE-2024-24930 1 Otwthemes 1 Buttons Shortcode And Widget 2024-08-01 6.5 Medium
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in OTWthemes.Com Buttons Shortcode and Widget allows Stored XSS.This issue affects Buttons Shortcode and Widget: from n/a through 1.16.