Archives: Reports

WordPress Plugin

rate-my-post

Vulnerability Type:

Cross-Site Scripting (XSS)

Date:

2022-12-20

The plugin contains a Cross-Site Scripting (XSS) vulnerability due to the plugin does not sanitize and escape some parameters, which makes it possible for authenticated users with a role as low as contributor to inject arbitrary web scripts into pages.

WordPress Plugin

genesis-columns-advanced

Vulnerability Type:

Cross-Site Scripting (XSS)

Date:

2022-12-20

The plugin contains a Cross-Site Scripting (XSS) vulnerability due to the plugin does not sanitize and escape some parameters, which makes it possible for authenticated users with a role as low as contributor to inject arbitrary web scripts into pages.

WordPress Plugin

pdf-viewer

Vulnerability Type:

Cross-Site Scripting (XSS)

Date:

2022-12-20

The plugin contains a Cross-Site Scripting (XSS) vulnerability due to the plugin does not sanitize and escape some parameters, which makes it possible for authenticated users with a role as low as contributor to inject arbitrary web scripts into pages.

WordPress Plugin

ibtana-visual-editor

Vulnerability Type:

Cross-Site Scripting (XSS)

Date:

2022-12-20

The plugin contains a Cross-Site Scripting (XSS) vulnerability due to the plugin does not sanitize and escape some parameters, which makes it possible for authenticated users with a role as low as contributor to inject arbitrary web scripts into pages.

WordPress Plugin

accordion-shortcodes

Vulnerability Type:

Cross-Site Scripting (XSS)

Date:

2022-12-20

The plugin contains a Cross-Site Scripting (XSS) vulnerability due to the plugin does not sanitize and escape some parameters, which makes it possible for authenticated users with a role as low as contributor to inject arbitrary web scripts into pages.

WordPress Plugin

facebook-page-feed-graph-api

Vulnerability Type:

Cross-Site Scripting (XSS)

Date:

2022-12-20

The plugin contains a Cross-Site Scripting (XSS) vulnerability due to the plugin does not sanitize and escape some parameters, which makes it possible for authenticated users with a role as low as contributor to inject arbitrary web scripts into pages.

WordPress Plugin

leaflet-maps-marker

Vulnerability Type:

Cross-Site Scripting (XSS)

Date:

2022-12-20

The plugin contains a Cross-Site Scripting (XSS) vulnerability due to the plugin does not sanitize and escape some parameters, which makes it possible for authenticated users with a role as low as contributor to inject arbitrary web scripts into pages.

WordPress Plugin

youtube-channel-gallery

Vulnerability Type:

Cross-Site Scripting (XSS)

Date:

2022-12-20

The plugin contains a Cross-Site Scripting (XSS) vulnerability due to the plugin does not sanitize and escape some parameters, which makes it possible for authenticated users with a role as low as contributor to inject arbitrary web scripts into pages.

WordPress Plugin

nd-shortcodes

Vulnerability Type:

Cross-Site Scripting (XSS)

Date:

2022-12-19

The plugin contains a Cross-Site Scripting (XSS) vulnerability due to the plugin does not sanitize and escape some parameters, which makes it possible for authenticated users with a role as low as contributor to inject arbitrary web scripts into pages.

WordPress Plugin

pdfjs-viewer-shortcode

Vulnerability Type:

Cross-Site Scripting (XSS)

Date:

2022-12-19

The plugin contains a Cross-Site Scripting (XSS) vulnerability due to the plugin does not sanitize and escape some parameters, which makes it possible for authenticated users with a role as low as contributor to inject arbitrary web scripts into pages.

WordPress Plugin

pixcodes

Vulnerability Type:

Cross-Site Scripting (XSS)

Date:

2022-12-19

The plugin contains a Cross-Site Scripting (XSS) vulnerability due to the plugin does not sanitize and escape some parameters, which makes it possible for authenticated users with a role as low as contributor to inject arbitrary web scripts into pages.

WordPress Plugin

gs-logo-slider

Vulnerability Type:

Cross-Site Scripting (XSS)

Date:

2022-12-19

The plugin contains a Cross-Site Scripting (XSS) vulnerability due to the plugin does not sanitize and escape some parameters, which makes it possible for authenticated users with a role as low as contributor to inject arbitrary web scripts into pages.

WordPress Plugin

login-logout-menu

Vulnerability Type:

Cross-Site Scripting (XSS)

Date:

2022-12-19

The plugin contains a Cross-Site Scripting (XSS) vulnerability due to the plugin does not sanitize and escape some parameters, which makes it possible for authenticated users with a role as low as contributor to inject arbitrary web scripts into pages.

WordPress Plugin

password-protect-page

Vulnerability Type:

Cross-Site Scripting (XSS)

Date:

2022-12-19

The plugin contains a Cross-Site Scripting (XSS) vulnerability due to the plugin does not sanitize and escape some parameters, which makes it possible for authenticated users with a role as low as contributor to inject arbitrary web scripts into pages.

WordPress Plugin

shiftnav-responsive-mobile-menu

Vulnerability Type:

Cross-Site Scripting (XSS)

Date:

2022-12-19

The plugin contains a Cross-Site Scripting (XSS) vulnerability due to the plugin does not sanitize and escape some parameters, which makes it possible for authenticated users with a role as low as contributor to inject arbitrary web scripts into pages.

WordPress Plugin

wp-ecommerce-paypal

Vulnerability Type:

Cross-Site Scripting (XSS)

Date:

2022-12-19

The plugin contains a Cross-Site Scripting (XSS) vulnerability due to the plugin does not sanitize and escape some parameters, which makes it possible for authenticated users with a role as low as contributor to inject arbitrary web scripts into pages.

WordPress Plugin

woo-product-slider

Vulnerability Type:

Cross-Site Scripting (XSS)

Date:

2022-12-19

The plugin contains a Cross-Site Scripting (XSS) vulnerability due to the plugin does not sanitize and escape some parameters, which makes it possible for authenticated users with a role as low as contributor to inject arbitrary web scripts into pages.

WordPress Plugin

wordpress-simple-paypal-shopping-cart

Vulnerability Type:

Cross-Site Scripting (XSS)

Date:

2022-12-19

The plugin contains a Cross-Site Scripting (XSS) vulnerability due to the plugin does not sanitize and escape some parameters, which makes it possible for authenticated users with a role as low as contributor to inject arbitrary web scripts into pages.

WordPress Plugin

media-element-html5-video-and-audio-player

Vulnerability Type:

Cross-Site Scripting (XSS)

Date:

2022-12-19

The plugin contains a Cross-Site Scripting (XSS) vulnerability due to the plugin does not sanitize and escape some parameters, which makes it possible for authenticated users with a role as low as contributor to inject arbitrary web scripts into pages.

WordPress Plugin

wp-dark-mode

Vulnerability Type:

Cross-Site Scripting (XSS)

Date:

2022-12-17

The plugin contains a Cross-Site Scripting (XSS) vulnerability due to the plugin does not sanitize and escape some parameters, which makes it possible for authenticated users with a role as low as contributor to inject arbitrary web scripts into pages.

WordPress Plugin

logo-slider-wp

Vulnerability Type:

Cross-Site Scripting (XSS)

Date:

2022-12-17

The plugin contains a Cross-Site Scripting (XSS) vulnerability due to the plugin does not sanitize and escape some parameters, which makes it possible for authenticated users with a role as low as contributor to inject arbitrary web scripts into pages.

WordPress Plugin

easy-appointments

Vulnerability Type:

Cross-Site Scripting (XSS)

Date:

2022-12-17

The plugin contains a Cross-Site Scripting (XSS) vulnerability due to the plugin does not sanitize and escape some parameters, which makes it possible for authenticated users with a role as low as contributor to inject arbitrary web scripts into pages.

WordPress Plugin

live-composer-page-builder

Vulnerability Type:

Cross-Site Scripting (XSS)

Date:

2022-12-17

The plugin contains a Cross-Site Scripting (XSS) vulnerability due to the plugin does not sanitize and escape some parameters, which makes it possible for authenticated users with a role as low as contributor to inject arbitrary web scripts into pages.

WordPress Plugin

top-10

Vulnerability Type:

Cross-Site Scripting (XSS)

Date:

2022-12-16

The plugin contains a Cross-Site Scripting (XSS) vulnerability due to the plugin does not sanitize and escape some parameters, which makes it possible for authenticated users with a role as low as contributor to inject arbitrary web scripts into pages.

WordPress Plugin

feedzy-rss-feeds

Vulnerability Type:

Cross-Site Scripting (XSS)

Date:

2022-12-16

The plugin contains a Cross-Site Scripting (XSS) vulnerability due to the plugin does not sanitize and escape some parameters, which makes it possible for authenticated users with a role as low as contributor to inject arbitrary web scripts into pages.