Archives: Reports

WordPress Plugin

real-kit

Vulnerability Type:

Cross-Site Scripting (XSS)

Date:

2023-01-09

The plugin contains a Cross-Site Scripting (XSS) vulnerability due to the plugin does not sanitize and escape some parameters, which makes it possible for authenticated users with a role as low as contributor to inject arbitrary web scripts into pages.

WordPress Plugin

scheduled-announcements-widget

Vulnerability Type:

Cross-Site Scripting (XSS)

Date:

2023-01-09

The plugin contains a Cross-Site Scripting (XSS) vulnerability due to the plugin does not sanitize and escape some parameters, which makes it possible for authenticated users with a role as low as contributor to inject arbitrary web scripts into pages.

WordPress Plugin

shortcode-for-font-awesome

Vulnerability Type:

Cross-Site Scripting (XSS)

Date:

2023-01-09

The plugin contains a Cross-Site Scripting (XSS) vulnerability due to the plugin does not sanitize and escape some parameters, which makes it possible for authenticated users with a role as low as contributor to inject arbitrary web scripts into pages.

WordPress Plugin

themify-portfolio-post

Vulnerability Type:

Cross-Site Scripting (XSS)

Date:

2023-01-09

The plugin contains a Cross-Site Scripting (XSS) vulnerability due to the plugin does not sanitize and escape some parameters, which makes it possible for authenticated users with a role as low as contributor to inject arbitrary web scripts into pages.

WordPress Plugin

wpjam-basic

Vulnerability Type:

Cross-Site Scripting (XSS)

Date:

2023-01-09

The plugin contains a Cross-Site Scripting (XSS) vulnerability due to the plugin does not sanitize and escape some parameters, which makes it possible for authenticated users with a role as low as contributor to inject arbitrary web scripts into pages.

WordPress Plugin

arconix-shortcodes

Vulnerability Type:

Cross-Site Scripting (XSS)

Date:

2023-01-09

The plugin contains a Cross-Site Scripting (XSS) vulnerability due to the plugin does not sanitize and escape some parameters, which makes it possible for authenticated users with a role as low as contributor to inject arbitrary web scripts into pages.

WordPress Plugin

wp-category-posts-list

Vulnerability Type:

Cross-Site Scripting (XSS)

Date:

2023-01-09

The plugin contains a Cross-Site Scripting (XSS) vulnerability due to the plugin does not sanitize and escape some parameters, which makes it possible for authenticated users with a role as low as contributor to inject arbitrary web scripts into pages.

WordPress Plugin

drop-shadow-boxes

Vulnerability Type:

Cross-Site Scripting (XSS)

Date:

2023-01-09

The plugin contains a Cross-Site Scripting (XSS) vulnerability due to the plugin does not sanitize and escape some parameters, which makes it possible for authenticated users with a role as low as contributor to inject arbitrary web scripts into pages.

WordPress Plugin

buddyforms

Vulnerability Type:

Cross-Site Scripting (XSS)

Date:

2023-01-09

The plugin contains a Cross-Site Scripting (XSS) vulnerability due to the plugin does not sanitize and escape some parameters, which makes it possible for authenticated users with a role as low as contributor to inject arbitrary web scripts into pages.

WordPress Plugin

add-posts-to-pages

Vulnerability Type:

Cross-Site Scripting (XSS)

Date:

2023-01-09

The plugin contains a Cross-Site Scripting (XSS) vulnerability due to the plugin does not sanitize and escape some parameters, which makes it possible for authenticated users with a role as low as contributor to inject arbitrary web scripts into pages.

WordPress Plugin

google-maps-v3-shortcode

Vulnerability Type:

Cross-Site Scripting (XSS)

Date:

2023-01-09

The plugin contains a Cross-Site Scripting (XSS) vulnerability due to the plugin does not sanitize and escape some parameters, which makes it possible for authenticated users with a role as low as contributor to inject arbitrary web scripts into pages.

WordPress Plugin

multi-column-tag-map

Vulnerability Type:

Cross-Site Scripting (XSS)

Date:

2023-01-09

The plugin contains a Cross-Site Scripting (XSS) vulnerability due to the plugin does not sanitize and escape some parameters, which makes it possible for authenticated users with a role as low as contributor to inject arbitrary web scripts into pages.

WordPress Plugin

simple-pdf-viewer

Vulnerability Type:

Cross-Site Scripting (XSS)

Date:

2023-01-09

The plugin contains a Cross-Site Scripting (XSS) vulnerability due to the plugin does not sanitize and escape some parameters, which makes it possible for authenticated users with a role as low as contributor to inject arbitrary web scripts into pages.

WordPress Plugin

portfolio-slideshow

Vulnerability Type:

Cross-Site Scripting (XSS)

Date:

2023-01-09

The plugin contains a Cross-Site Scripting (XSS) vulnerability due to the plugin does not sanitize and escape some parameters, which makes it possible for authenticated users with a role as low as contributor to inject arbitrary web scripts into pages.

WordPress Plugin

rating-widget

Vulnerability Type:

Cross-Site Scripting (XSS)

Date:

2023-01-09

The plugin contains a Cross-Site Scripting (XSS) vulnerability due to the plugin does not sanitize and escape some parameters, which makes it possible for authenticated users with a role as low as contributor to inject arbitrary web scripts into pages.

WordPress Plugin

wpdm-gutenberg-blocks

Vulnerability Type:

Cross-Site Scripting (XSS)

Date:

2023-01-09

The plugin contains a Cross-Site Scripting (XSS) vulnerability due to the plugin does not sanitize and escape some parameters, which makes it possible for authenticated users with a role as low as contributor to inject arbitrary web scripts into pages.

WordPress Plugin

owl-carousel

Vulnerability Type:

Cross-Site Scripting (XSS)

Date:

2023-01-09

The plugin contains a Cross-Site Scripting (XSS) vulnerability due to the plugin does not sanitize and escape some parameters, which makes it possible for authenticated users with a role as low as contributor to inject arbitrary web scripts into pages.

WordPress Plugin

ultimate-wp-query-search-filter

Vulnerability Type:

Cross-Site Scripting (XSS)

Date:

2023-01-09

The plugin contains a Cross-Site Scripting (XSS) vulnerability due to the plugin does not sanitize and escape some parameters, which makes it possible for authenticated users with a role as low as contributor to inject arbitrary web scripts into pages.

WordPress Plugin

responsive-tabs-for-wpbakery

Vulnerability Type:

Cross-Site Scripting (XSS)

Date:

2023-01-08

The plugin contains a Cross-Site Scripting (XSS) vulnerability due to the plugin does not sanitize and escape some parameters, which makes it possible for authenticated users with a role as low as contributor to inject arbitrary web scripts into pages.

WordPress Plugin

pricing-tables-for-wpbakery-page-builder

Vulnerability Type:

Cross-Site Scripting (XSS)

Date:

2023-01-08

The plugin contains a Cross-Site Scripting (XSS) vulnerability due to the plugin does not sanitize and escape some parameters, which makes it possible for authenticated users with a role as low as contributor to inject arbitrary web scripts into pages.

WordPress Plugin

wp-multi-store-locator

Vulnerability Type:

Cross-Site Scripting (XSS)

Date:

2023-01-08

The plugin contains a Cross-Site Scripting (XSS) vulnerability due to the plugin does not sanitize and escape some parameters, which makes it possible for authenticated users with a role as low as contributor to inject arbitrary web scripts into pages.

WordPress Plugin

embedstories

Vulnerability Type:

Cross-Site Scripting (XSS)

Date:

2023-01-08

The plugin contains a Cross-Site Scripting (XSS) vulnerability due to the plugin does not sanitize and escape some parameters, which makes it possible for authenticated users with a role as low as contributor to inject arbitrary web scripts into pages.

WordPress Plugin

embedalbum-pro

Vulnerability Type:

Cross-Site Scripting (XSS)

Date:

2023-01-08

The plugin contains a Cross-Site Scripting (XSS) vulnerability due to the plugin does not sanitize and escape some parameters, which makes it possible for authenticated users with a role as low as contributor to inject arbitrary web scripts into pages.

WordPress Plugin

wpb-advanced-faq

Vulnerability Type:

Cross-Site Scripting (XSS)

Date:

2023-01-08

The plugin contains a Cross-Site Scripting (XSS) vulnerability due to the plugin does not sanitize and escape some parameters, which makes it possible for authenticated users with a role as low as contributor to inject arbitrary web scripts into pages.

WordPress Plugin

gotowp

Vulnerability Type:

Cross-Site Scripting (XSS)

Date:

2023-01-08

The plugin contains a Cross-Site Scripting (XSS) vulnerability due to the plugin does not sanitize and escape some parameters, which makes it possible for authenticated users with a role as low as contributor to inject arbitrary web scripts into pages.