Security
Headlines
HeadlinesLatestCVEs

Tag

#wordpress

CVE-2023-23833: WordPress Drop Shadow Boxes plugin <= 1.7.10 - Cross Site Scripting (XSS) vulnerability - Patchstack

Auth. (contributor+) Cross-Site Scripting (XSS) vulnerability in Steven Henty Drop Shadow Boxes plugin <= 1.7.10 versions.

CVE
#xss#vulnerability#web#wordpress#auth
WordPress Page Builder KingComposer 2.9.6 Open Redirection

WordPress Page Builder KingComposer plugin version 2.9.6 suffers from an open redirection vulnerability.

WordPress Image Optimization 3.8.2 Open Redirection

WordPress Image Optimization plugin version 3.8.2 suffers from an open redirection vulnerability.

CVE-2023-3344

The Auto Location for WP Job Manager via Google WordPress plugin before 1.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

CVE-2023-3248

The All-in-one Floating Contact Form WordPress plugin before 2.1.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

CVE-2023-2761

The User Activity Log WordPress plugin before 1.6.3 does not properly sanitise and escape the `txtsearch` parameter before using it in a SQL statement in some admin pages, leading to a SQL injection exploitable by high privilege users such as admin.

CVE-2023-2309

The wpForo Forum WordPress plugin before 2.1.9 does not escape some request parameters while in debug mode, leading to a Reflected Cross-Site Scripting vulnerability.

WordPress Page Builder KingComposer 2.9.5 Open Redirection

WordPress Page Builder KingComposer plugin version 2.9.5 suffers from an open redirection vulnerability.