Security
Headlines
HeadlinesLatestCVEs

Headline

CVE-2022-34650: Team

Multiple Authenticated (contributor or higher user role) Stored Cross-Site Scripting (XSS) vulnerabilities in wpWax Team plugin <= 1.2.6 at WordPress.

CVE
#xss#vulnerability#wordpress#auth
  • Details
  • Reviews
  • Support
  • Development

This plugin has been closed as of May 3, 2022 and is not available for download. Reason: Licensing/Trademark Violation.

I looked through plenty of plugins to display our team the way I wanted and there was always something missing. This one has it all: a great grid, pop-up more info on each person, nicely displayed social icons, additional fields for skills and more info. Really cool and super easy to use! The only two little things that were missing in our experience were: 1) some customisable features are not responsive (like font size of colour, even in the pro version) 2) we needed some additional customisation, like removing animation, changing titles of additional fields, etc. The plug-in support has helped us with everything adding code directly on the site! Super helpful and nice, definitely recommended 🙂

The plugin has several options with which one can modify the look of it. I especially want to complement the great support I got. I asked whether it would be possible to get a new feature to the plugin and it didn’t take long and they had updated the plugin to include the requested feature. Great plugin and a great team behind it!

Read all 2 reviews

“Team” is open source software. The following people have contributed to this plugin.

Contributors

  • wpWax

CVE: Latest News

CVE-2023-50976: Transactions API Authorization by oleiman · Pull Request #14969 · redpanda-data/redpanda
CVE-2023-6905
CVE-2023-6903
CVE-2023-6904
CVE-2023-3907