Archives: Reports

WordPress Plugin

uncanny-learndash-toolkit

Vulnerability Type:

Cross-Site Request Forgery (CSRF)

Date:

2023-01-11

The plugin contains a Cross-Site Request Forgery (CSRF) vulnerability due to a missing nonce check in the auto_plugin_install AJAX action, which makes it possible for attackers to install and activate arbitrary plugins from WordPress.org repository via a forged request if they can trick an administrator into performing an action such as clicking on a link.

WordPress Plugin

mail-subscribe-list

Vulnerability Type:

Cross-Site Scripting (XSS)

Date:

2023-01-11

The plugin contains a Cross-Site Scripting (XSS) vulnerability due to the plugin does not sanitize and escape some parameters, which makes it possible for authenticated users with a role as low as contributor to inject arbitrary web scripts into pages.

WordPress Plugin

uji-popup

Vulnerability Type:

Cross-Site Scripting (XSS)

Date:

2023-01-11

The plugin contains a Cross-Site Scripting (XSS) vulnerability due to the plugin does not sanitize and escape some parameters, which makes it possible for authenticated users with a role as low as contributor to inject arbitrary web scripts into pages.

WordPress Plugin

convertbox-auto-embed

Vulnerability Type:

Cross-Site Scripting (XSS)

Date:

2023-01-11

The plugin contains a Cross-Site Scripting (XSS) vulnerability due to the plugin does not sanitize and escape some parameters, which makes it possible for authenticated users with a role as low as contributor to inject arbitrary web scripts into pages.

WordPress Plugin

fancy-facebook-comments

Vulnerability Type:

Cross-Site Scripting (XSS)

Date:

2023-01-11

The plugin contains a Cross-Site Scripting (XSS) vulnerability due to the plugin does not sanitize and escape some parameters, which makes it possible for authenticated users with a role as low as contributor to inject arbitrary web scripts into pages.

WordPress Plugin

brands-for-woocommerce

Vulnerability Type:

Cross-Site Scripting (XSS)

Date:

2023-01-11

The plugin contains a Cross-Site Scripting (XSS) vulnerability due to the plugin does not sanitize and escape some parameters, which makes it possible for authenticated users with a role as low as contributor to inject arbitrary web scripts into pages.

WordPress Plugin

file-gallery

Vulnerability Type:

Cross-Site Scripting (XSS)

Date:

2023-01-11

The plugin contains a Cross-Site Scripting (XSS) vulnerability due to the plugin does not sanitize and escape some parameters, which makes it possible for authenticated users with a role as low as contributor to inject arbitrary web scripts into pages.

WordPress Plugin

ht-slider-for-elementor

Vulnerability Type:

Cross-Site Request Forgery (CSRF)

Date:

2023-01-10

The plugin contains a Cross-Site Request Forgery (CSRF) vulnerability due to a missing nonce check in the ht-slider_ajax_plugin_activation AJAX action, which makes it possible for attackers to activate arbitrary plugins present on the blog via a forged request if they can trick an administrator into performing an action such as clicking on a link.

WordPress Plugin

ht-contactform

Vulnerability Type:

Cross-Site Request Forgery (CSRF)

Date:

2023-01-10

The plugin contains a Cross-Site Request Forgery (CSRF) vulnerability due to a missing nonce check in the ht-contactform_ajax_plugin_activation AJAX action, which makes it possible for attackers to activate arbitrary plugins present on the blog via a forged request if they can trick an administrator into performing an action such as clicking on a link.

WordPress Plugin

wp-insurance

Vulnerability Type:

Cross-Site Request Forgery (CSRF)

Date:

2023-01-10

The plugin contains a Cross-Site Request Forgery (CSRF) vulnerability due to a missing nonce check in the wpinsurance_ajax_plugin_activation AJAX action, which makes it possible for attackers to activate arbitrary plugins present on the blog via a forged request if they can trick an administrator into performing an action such as clicking on a link.

WordPress Plugin

ht-event

Vulnerability Type:

Cross-Site Request Forgery (CSRF)

Date:

2023-01-10

The plugin contains a Cross-Site Request Forgery (CSRF) vulnerability due to a missing nonce check in the htevent_ajax_plugin_activation AJAX action, which makes it possible for attackers to activate arbitrary plugins present on the blog via a forged request if they can trick an administrator into performing an action such as clicking on a link.

WordPress Plugin

ht-portfolio

Vulnerability Type:

Cross-Site Request Forgery (CSRF)

Date:

2023-01-10

The plugin contains a Cross-Site Request Forgery (CSRF) vulnerability due to a missing nonce check in the htportfolio_ajax_plugin_activation AJAX action, which makes it possible for attackers to activate arbitrary plugins present on the blog via a forged request if they can trick an administrator into performing an action such as clicking on a link.

WordPress Plugin

wp-education

Vulnerability Type:

Cross-Site Request Forgery (CSRF)

Date:

2023-01-10

The plugin contains a Cross-Site Request Forgery (CSRF) vulnerability due to a missing nonce check in the wpeducation_ajax_plugin_activation AJAX action, which makes it possible for attackers to activate arbitrary plugins present on the blog via a forged request if they can trick an administrator into performing an action such as clicking on a link.

WordPress Plugin

quickswish

Vulnerability Type:

Cross-Site Request Forgery (CSRF)

Date:

2023-01-10

The plugin contains a Cross-Site Request Forgery (CSRF) vulnerability due to a missing nonce check in the quickswish_ajax_plugin_activation AJAX action, which makes it possible for attackers to activate arbitrary plugins present on the blog via a forged request if they can trick an administrator into performing an action such as clicking on a link.

WordPress Plugin

wp-film-studio

Vulnerability Type:

Cross-Site Request Forgery (CSRF)

Date:

2023-01-10

The plugin contains a Cross-Site Request Forgery (CSRF) vulnerability due to a missing nonce check in the wpfilm-studio_ajax_plugin_activation AJAX action, which makes it possible for attackers to activate arbitrary plugins present on the blog via a forged request if they can trick an administrator into performing an action such as clicking on a link.

WordPress Plugin

wp-news-magazine

Vulnerability Type:

Cross-Site Request Forgery (CSRF)

Date:

2023-01-10

The plugin contains a Cross-Site Request Forgery (CSRF) vulnerability due to a missing nonce check in the ht-magazine_ajax_plugin_activation AJAX action, which makes it possible for attackers to activate arbitrary plugins present on the blog via a forged request if they can trick an administrator into performing an action such as clicking on a link.

WordPress Plugin

99fy-core

Vulnerability Type:

Cross-Site Request Forgery (CSRF)

Date:

2023-01-10

The plugin contains a Cross-Site Request Forgery (CSRF) vulnerability due to a missing nonce check in the 99fy_ajax_plugin_activation AJAX action, which makes it possible for attackers to activate arbitrary plugins present on the blog via a forged request if they can trick an administrator into performing an action such as clicking on a link.

WordPress Plugin

wp-politic

Vulnerability Type:

Cross-Site Request Forgery (CSRF)

Date:

2023-01-10

The plugin contains a Cross-Site Request Forgery (CSRF) vulnerability due to a missing nonce check in the wppolitic_ajax_plugin_activation AJAX action, which makes it possible for attackers to activate arbitrary plugins present on the blog via a forged request if they can trick an administrator into performing an action such as clicking on a link.

WordPress Plugin

ever-compare

Vulnerability Type:

Cross-Site Request Forgery (CSRF)

Date:

2023-01-10

The plugin contains a Cross-Site Request Forgery (CSRF) vulnerability due to a missing nonce check in the ever-compare_ajax_plugin_activation AJAX action, which makes it possible for attackers to activate arbitrary plugins present on the blog via a forged request if they can trick an administrator into performing an action such as clicking on a link.

WordPress Plugin

ooohboi-steroids-for-elementor

Vulnerability Type:

Missing Authorization

Date:

2023-01-10

The plugin contains a Missing Authorization vulnerability due to a missing capability check in the exopite-sof-file-batch-delete AJAX action, which makes it possible for authenticated attackers with a role as low as subscriber to delete arbitrary attachment.

WordPress Plugin

wp-shamsi

Vulnerability Type:

Missing Authorization

Date:

2023-01-10

The plugin contains a Missing Authorization vulnerability due to a missing capability check in the exopite-sof-file-batch-delete AJAX action, which makes it possible for authenticated attackers with a role as low as subscriber to delete arbitrary attachment.

WordPress Plugin

post-shortcode

Vulnerability Type:

Cross-Site Scripting (XSS)

Date:

2023-01-10

The plugin contains a Cross-Site Scripting (XSS) vulnerability due to the plugin does not sanitize and escape some parameters, which makes it possible for authenticated users with a role as low as contributor to inject arbitrary web scripts into pages.

WordPress Plugin

custom-post-type-list-shortcode

Vulnerability Type:

Cross-Site Scripting (XSS)

Date:

2023-01-10

The plugin contains a Cross-Site Scripting (XSS) vulnerability due to the plugin does not sanitize and escape some parameters, which makes it possible for authenticated users with a role as low as contributor to inject arbitrary web scripts into pages.

WordPress Plugin

wp-d3

Vulnerability Type:

Cross-Site Scripting (XSS)

Date:

2023-01-10

The plugin contains a Cross-Site Scripting (XSS) vulnerability due to the plugin does not sanitize and escape some parameters, which makes it possible for authenticated users with a role as low as contributor to inject arbitrary web scripts into pages.

WordPress Plugin

product-slider-for-woocommerce-lite

Vulnerability Type:

Cross-Site Scripting (XSS)

Date:

2023-01-10

The plugin contains a Cross-Site Scripting (XSS) vulnerability due to the plugin does not sanitize and escape some parameters, which makes it possible for authenticated users with a role as low as contributor to inject arbitrary web scripts into pages.