Archives: Reports
CVE ID:
CVE-2023-23714
WordPress Plugin
uncanny-learndash-toolkit
Vulnerability Type:
Cross-Site Request Forgery (CSRF)
Date:
2023-01-11
The plugin contains a Cross-Site Request Forgery (CSRF) vulnerability due to a missing nonce check in the auto_plugin_install AJAX action, which makes it possible for attackers to install and activate arbitrary plugins from WordPress.org repository via a forged request if they can trick an administrator into performing an action such as clicking on a link.
CVE ID:
CVE-2023-23657
WordPress Plugin
mail-subscribe-list
Vulnerability Type:
Cross-Site Scripting (XSS)
Date:
2023-01-11
The plugin contains a Cross-Site Scripting (XSS) vulnerability due to the plugin does not sanitize and escape some parameters, which makes it possible for authenticated users with a role as low as contributor to inject arbitrary web scripts into pages.
CVE ID:
CVE-2023-23641
WordPress Plugin
uji-popup
Vulnerability Type:
Cross-Site Scripting (XSS)
Date:
2023-01-11
The plugin contains a Cross-Site Scripting (XSS) vulnerability due to the plugin does not sanitize and escape some parameters, which makes it possible for authenticated users with a role as low as contributor to inject arbitrary web scripts into pages.
CVE ID:
CVE-2023-23664
WordPress Plugin
convertbox-auto-embed
Vulnerability Type:
Cross-Site Scripting (XSS)
Date:
2023-01-11
The plugin contains a Cross-Site Scripting (XSS) vulnerability due to the plugin does not sanitize and escape some parameters, which makes it possible for authenticated users with a role as low as contributor to inject arbitrary web scripts into pages.
CVE ID:
CVE-2023-23670
WordPress Plugin
fancy-facebook-comments
Vulnerability Type:
Cross-Site Scripting (XSS)
Date:
2023-01-11
The plugin contains a Cross-Site Scripting (XSS) vulnerability due to the plugin does not sanitize and escape some parameters, which makes it possible for authenticated users with a role as low as contributor to inject arbitrary web scripts into pages.
CVE ID:
CVE-2023-23667
WordPress Plugin
brands-for-woocommerce
Vulnerability Type:
Cross-Site Scripting (XSS)
Date:
2023-01-11
The plugin contains a Cross-Site Scripting (XSS) vulnerability due to the plugin does not sanitize and escape some parameters, which makes it possible for authenticated users with a role as low as contributor to inject arbitrary web scripts into pages.
CVE ID:
CVE-2023-23676
WordPress Plugin
file-gallery
Vulnerability Type:
Cross-Site Scripting (XSS)
Date:
2023-01-11
The plugin contains a Cross-Site Scripting (XSS) vulnerability due to the plugin does not sanitize and escape some parameters, which makes it possible for authenticated users with a role as low as contributor to inject arbitrary web scripts into pages.
CVE ID:
CVE-2023-0495
WordPress Plugin
ht-slider-for-elementor
Vulnerability Type:
Cross-Site Request Forgery (CSRF)
Date:
2023-01-10
The plugin contains a Cross-Site Request Forgery (CSRF) vulnerability due to a missing nonce check in the ht-slider_ajax_plugin_activation AJAX action, which makes it possible for attackers to activate arbitrary plugins present on the blog via a forged request if they can trick an administrator into performing an action such as clicking on a link.
CVE ID:
CVE-2023-0484
WordPress Plugin
ht-contactform
Vulnerability Type:
Cross-Site Request Forgery (CSRF)
Date:
2023-01-10
The plugin contains a Cross-Site Request Forgery (CSRF) vulnerability due to a missing nonce check in the ht-contactform_ajax_plugin_activation AJAX action, which makes it possible for attackers to activate arbitrary plugins present on the blog via a forged request if they can trick an administrator into performing an action such as clicking on a link.
CVE ID:
CVE-2023-0501
WordPress Plugin
wp-insurance
Vulnerability Type:
Cross-Site Request Forgery (CSRF)
Date:
2023-01-10
The plugin contains a Cross-Site Request Forgery (CSRF) vulnerability due to a missing nonce check in the wpinsurance_ajax_plugin_activation AJAX action, which makes it possible for attackers to activate arbitrary plugins present on the blog via a forged request if they can trick an administrator into performing an action such as clicking on a link.
CVE ID:
CVE-2023-0496
WordPress Plugin
ht-event
Vulnerability Type:
Cross-Site Request Forgery (CSRF)
Date:
2023-01-10
The plugin contains a Cross-Site Request Forgery (CSRF) vulnerability due to a missing nonce check in the htevent_ajax_plugin_activation AJAX action, which makes it possible for attackers to activate arbitrary plugins present on the blog via a forged request if they can trick an administrator into performing an action such as clicking on a link.
CVE ID:
CVE-2023-0497
WordPress Plugin
ht-portfolio
Vulnerability Type:
Cross-Site Request Forgery (CSRF)
Date:
2023-01-10
The plugin contains a Cross-Site Request Forgery (CSRF) vulnerability due to a missing nonce check in the htportfolio_ajax_plugin_activation AJAX action, which makes it possible for attackers to activate arbitrary plugins present on the blog via a forged request if they can trick an administrator into performing an action such as clicking on a link.
CVE ID:
CVE-2023-0498
WordPress Plugin
wp-education
Vulnerability Type:
Cross-Site Request Forgery (CSRF)
Date:
2023-01-10
The plugin contains a Cross-Site Request Forgery (CSRF) vulnerability due to a missing nonce check in the wpeducation_ajax_plugin_activation AJAX action, which makes it possible for attackers to activate arbitrary plugins present on the blog via a forged request if they can trick an administrator into performing an action such as clicking on a link.
CVE ID:
CVE-2023-0499
WordPress Plugin
quickswish
Vulnerability Type:
Cross-Site Request Forgery (CSRF)
Date:
2023-01-10
The plugin contains a Cross-Site Request Forgery (CSRF) vulnerability due to a missing nonce check in the quickswish_ajax_plugin_activation AJAX action, which makes it possible for attackers to activate arbitrary plugins present on the blog via a forged request if they can trick an administrator into performing an action such as clicking on a link.
CVE ID:
CVE-2023-0500
WordPress Plugin
wp-film-studio
Vulnerability Type:
Cross-Site Request Forgery (CSRF)
Date:
2023-01-10
The plugin contains a Cross-Site Request Forgery (CSRF) vulnerability due to a missing nonce check in the wpfilm-studio_ajax_plugin_activation AJAX action, which makes it possible for attackers to activate arbitrary plugins present on the blog via a forged request if they can trick an administrator into performing an action such as clicking on a link.
CVE ID:
CVE-2023-0502
WordPress Plugin
wp-news-magazine
Vulnerability Type:
Cross-Site Request Forgery (CSRF)
Date:
2023-01-10
The plugin contains a Cross-Site Request Forgery (CSRF) vulnerability due to a missing nonce check in the ht-magazine_ajax_plugin_activation AJAX action, which makes it possible for attackers to activate arbitrary plugins present on the blog via a forged request if they can trick an administrator into performing an action such as clicking on a link.
CVE ID:
CVE-2023-0503
WordPress Plugin
99fy-core
Vulnerability Type:
Cross-Site Request Forgery (CSRF)
Date:
2023-01-10
The plugin contains a Cross-Site Request Forgery (CSRF) vulnerability due to a missing nonce check in the 99fy_ajax_plugin_activation AJAX action, which makes it possible for attackers to activate arbitrary plugins present on the blog via a forged request if they can trick an administrator into performing an action such as clicking on a link.
CVE ID:
CVE-2023-0504
WordPress Plugin
wp-politic
Vulnerability Type:
Cross-Site Request Forgery (CSRF)
Date:
2023-01-10
The plugin contains a Cross-Site Request Forgery (CSRF) vulnerability due to a missing nonce check in the wppolitic_ajax_plugin_activation AJAX action, which makes it possible for attackers to activate arbitrary plugins present on the blog via a forged request if they can trick an administrator into performing an action such as clicking on a link.
CVE ID:
CVE-2023-0505
WordPress Plugin
ever-compare
Vulnerability Type:
Cross-Site Request Forgery (CSRF)
Date:
2023-01-10
The plugin contains a Cross-Site Request Forgery (CSRF) vulnerability due to a missing nonce check in the ever-compare_ajax_plugin_activation AJAX action, which makes it possible for attackers to activate arbitrary plugins present on the blog via a forged request if they can trick an administrator into performing an action such as clicking on a link.
CVE ID:
CVE-2023-0336
WordPress Plugin
ooohboi-steroids-for-elementor
Vulnerability Type:
Missing Authorization
Date:
2023-01-10
The plugin contains a Missing Authorization vulnerability due to a missing capability check in the exopite-sof-file-batch-delete AJAX action, which makes it possible for authenticated attackers with a role as low as subscriber to delete arbitrary attachment.
CVE ID:
CVE-2023-0335
WordPress Plugin
wp-shamsi
Vulnerability Type:
Missing Authorization
Date:
2023-01-10
The plugin contains a Missing Authorization vulnerability due to a missing capability check in the exopite-sof-file-batch-delete AJAX action, which makes it possible for authenticated attackers with a role as low as subscriber to delete arbitrary attachment.
CVE ID:
CVE-2023-0526
WordPress Plugin
post-shortcode
Vulnerability Type:
Cross-Site Scripting (XSS)
Date:
2023-01-10
The plugin contains a Cross-Site Scripting (XSS) vulnerability due to the plugin does not sanitize and escape some parameters, which makes it possible for authenticated users with a role as low as contributor to inject arbitrary web scripts into pages.
CVE ID:
CVE-2023-0542
WordPress Plugin
custom-post-type-list-shortcode
Vulnerability Type:
Cross-Site Scripting (XSS)
Date:
2023-01-10
The plugin contains a Cross-Site Scripting (XSS) vulnerability due to the plugin does not sanitize and escape some parameters, which makes it possible for authenticated users with a role as low as contributor to inject arbitrary web scripts into pages.
CVE ID:
CVE-2023-0536
WordPress Plugin
wp-d3
Vulnerability Type:
Cross-Site Scripting (XSS)
Date:
2023-01-10
The plugin contains a Cross-Site Scripting (XSS) vulnerability due to the plugin does not sanitize and escape some parameters, which makes it possible for authenticated users with a role as low as contributor to inject arbitrary web scripts into pages.
CVE ID:
CVE-2023-0537
WordPress Plugin
product-slider-for-woocommerce-lite
Vulnerability Type:
Cross-Site Scripting (XSS)
Date:
2023-01-10
The plugin contains a Cross-Site Scripting (XSS) vulnerability due to the plugin does not sanitize and escape some parameters, which makes it possible for authenticated users with a role as low as contributor to inject arbitrary web scripts into pages.