Archives: Reports

WordPress Plugin

salient-shortcodes

Vulnerability Type:

Cross-Site Scripting (XSS)

Date:

2024-04-15

The plugin contains a Cross-Site Scripting (XSS) vulnerability due to the plugin does not sanitize and escape some parameters, which makes it possible for authenticated users with a role as low as contributor to inject arbitrary web scripts into pages.

WordPress Plugin

easyrotator-for-wordpress

Vulnerability Type:

Cross-Site Scripting (XSS)

Date:

2023-10-23

The plugin contains a Cross-Site Scripting (XSS) vulnerability due to the plugin does not sanitize and escape some parameters, which makes it possible for authenticated users with a role as low as contributor to inject arbitrary web scripts into pages.

WordPress Plugin

wp-facebook-messenger

Vulnerability Type:

Cross-Site Scripting (XSS)

Date:

2023-10-23

The plugin contains a Cross-Site Scripting (XSS) vulnerability due to the plugin does not sanitize and escape some parameters, which makes it possible for authenticated users with a role as low as contributor to inject arbitrary web scripts into pages.

WordPress Plugin

powr-pack

Vulnerability Type:

Cross-Site Scripting (XSS)

Date:

2023-10-23

The plugin contains a Cross-Site Scripting (XSS) vulnerability due to the plugin does not sanitize and escape some parameters, which makes it possible for authenticated users with a role as low as contributor to inject arbitrary web scripts into pages.

WordPress Plugin

very-simple-google-maps

Vulnerability Type:

Cross-Site Scripting (XSS)

Date:

2023-10-23

The plugin contains a Cross-Site Scripting (XSS) vulnerability due to the plugin does not sanitize and escape some parameters, which makes it possible for authenticated users with a role as low as contributor to inject arbitrary web scripts into pages.

WordPress Plugin

telephone-number-linker

Vulnerability Type:

Cross-Site Scripting (XSS)

Date:

2023-10-23

The plugin contains a Cross-Site Scripting (XSS) vulnerability due to the plugin does not sanitize and escape some parameters, which makes it possible for authenticated users with a role as low as contributor to inject arbitrary web scripts into pages.

WordPress Plugin

wp-post-columns

Vulnerability Type:

Cross-Site Scripting (XSS)

Date:

2023-10-21

The plugin contains a Cross-Site Scripting (XSS) vulnerability due to the plugin does not sanitize and escape some parameters, which makes it possible for authenticated users with a role as low as contributor to inject arbitrary web scripts into pages.

WordPress Plugin

seo-slider

Vulnerability Type:

Cross-Site Scripting (XSS)

Date:

2023-10-21

The plugin contains a Cross-Site Scripting (XSS) vulnerability due to the plugin does not sanitize and escape some parameters, which makes it possible for authenticated users with a role as low as contributor to inject arbitrary web scripts into pages.

WordPress Plugin

cpo-shortcodes

Vulnerability Type:

Cross-Site Scripting (XSS)

Date:

2023-10-20

The plugin contains a Cross-Site Scripting (XSS) vulnerability due to the plugin does not sanitize and escape some parameters, which makes it possible for authenticated users with a role as low as contributor to inject arbitrary web scripts into pages.

WordPress Plugin

vk-filter-search

Vulnerability Type:

Cross-Site Scripting (XSS)

Date:

2023-10-20

The plugin contains a Cross-Site Scripting (XSS) vulnerability due to the plugin does not sanitize and escape some parameters, which makes it possible for authenticated users with a role as low as contributor to inject arbitrary web scripts into pages.

WordPress Plugin

vk-blocks

Vulnerability Type:

Cross-Site Scripting (XSS)

Date:

2023-10-20

The plugin contains a Cross-Site Scripting (XSS) vulnerability due to the plugin does not sanitize and escape some parameters, which makes it possible for authenticated users with a role as low as contributor to inject arbitrary web scripts into pages.

WordPress Plugin

gift-up

Vulnerability Type:

Cross-Site Scripting (XSS)

Date:

2023-10-20

The plugin contains a Cross-Site Scripting (XSS) vulnerability due to the plugin does not sanitize and escape some parameters, which makes it possible for authenticated users with a role as low as contributor to inject arbitrary web scripts into pages.

WordPress Plugin

featured-image-caption

Vulnerability Type:

Cross-Site Scripting (XSS)

Date:

2023-10-19

The plugin contains a Cross-Site Scripting (XSS) vulnerability due to the plugin does not sanitize and escape some parameters, which makes it possible for authenticated users with a role as low as contributor to inject arbitrary web scripts into pages.

WordPress Plugin

tabs-pro

Vulnerability Type:

Cross-Site Scripting (XSS)

Date:

2023-10-18

The plugin contains a Cross-Site Scripting (XSS) vulnerability due to the plugin does not sanitize and escape some parameters, which makes it possible for authenticated users with a role as low as contributor to inject arbitrary web scripts into pages.

WordPress Plugin

accordions-wp

Vulnerability Type:

Cross-Site Scripting (XSS)

Date:

2023-10-18

The plugin contains a Cross-Site Scripting (XSS) vulnerability due to the plugin does not sanitize and escape some parameters, which makes it possible for authenticated users with a role as low as contributor to inject arbitrary web scripts into pages.

WordPress Plugin

whatsapp

Vulnerability Type:

Cross-Site Scripting (XSS)

Date:

2023-10-18

The plugin contains a Cross-Site Scripting (XSS) vulnerability due to the plugin does not sanitize and escape some parameters, which makes it possible for authenticated users with a role as low as contributor to inject arbitrary web scripts into pages.

WordPress Plugin

skype-online-status

Vulnerability Type:

Cross-Site Scripting (XSS)

Date:

2023-10-17

The plugin contains a Cross-Site Scripting (XSS) vulnerability due to the plugin does not sanitize and escape some parameters, which makes it possible for authenticated users with a role as low as contributor to inject arbitrary web scripts into pages.

WordPress Plugin

payment-forms-for-paystack

Vulnerability Type:

Cross-Site Scripting (XSS)

Date:

2023-10-17

The plugin contains a Cross-Site Scripting (XSS) vulnerability due to the plugin does not sanitize and escape some parameters, which makes it possible for authenticated users with a role as low as contributor to inject arbitrary web scripts into pages.

WordPress Plugin

team-showcase

Vulnerability Type:

Cross-Site Scripting (XSS)

Date:

2023-10-17

The plugin contains a Cross-Site Scripting (XSS) vulnerability due to the plugin does not sanitize and escape some parameters, which makes it possible for authenticated users with a role as low as contributor to inject arbitrary web scripts into pages.

WordPress Plugin

wp-sponsors

Vulnerability Type:

Cross-Site Scripting (XSS)

Date:

2023-10-16

The plugin contains a Cross-Site Scripting (XSS) vulnerability due to the plugin does not sanitize and escape some parameters, which makes it possible for authenticated users with a role as low as contributor to inject arbitrary web scripts into pages.

WordPress Plugin

garden-gnome-package

Vulnerability Type:

Cross-Site Scripting (XSS)

Date:

2023-10-16

The plugin contains a Cross-Site Scripting (XSS) vulnerability due to the plugin does not sanitize and escape some parameters, which makes it possible for authenticated users with a role as low as contributor to inject arbitrary web scripts into pages.

WordPress Plugin

sendpress

Vulnerability Type:

Cross-Site Scripting (XSS)

Date:

2023-10-14

The plugin contains a Cross-Site Scripting (XSS) vulnerability due to the plugin does not sanitize and escape some parameters, which makes it possible for authenticated users with a role as low as contributor to inject arbitrary web scripts into pages.

WordPress Plugin

interact-quiz-embed

Vulnerability Type:

Cross-Site Scripting (XSS)

Date:

2023-10-14

The plugin contains a Cross-Site Scripting (XSS) vulnerability due to the plugin does not sanitize and escape some parameters, which makes it possible for authenticated users with a role as low as contributor to inject arbitrary web scripts into pages.

WordPress Plugin

super-testimonial

Vulnerability Type:

Cross-Site Scripting (XSS)

Date:

2023-10-14

The plugin contains a Cross-Site Scripting (XSS) vulnerability due to the plugin does not sanitize and escape some parameters, which makes it possible for authenticated users with a role as low as contributor to inject arbitrary web scripts into pages.

WordPress Plugin

theme-switcha

Vulnerability Type:

Cross-Site Scripting (XSS)

Date:

2023-10-14

The plugin contains a Cross-Site Scripting (XSS) vulnerability due to the plugin does not sanitize and escape some parameters, which makes it possible for authenticated users with a role as low as contributor to inject arbitrary web scripts into pages.