Security
Headlines
HeadlinesLatestCVEs

Source

CVE

CVE-2023-32793: WordPress WooCommerce Pre-Orders plugin <= 2.0.0 - Contributor+ Stored Cross Site Scripting (XSS) vulnerability - Patchstack

Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in WooCommerce WooCommerce Pre-Orders plugin <= 2.0.0 versions.

CVE
#xss#vulnerability#web#wordpress#auth
CVE-2023-32746: WordPress WooCommerce Brands plugin <= 1.6.45 - Contributor+ Stored Cross Site Scripting (XSS) vulnerability - Patchstack

Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in WooCommerce WooCommerce Brands plugin <= 1.6.45 versions.

CVE-2023-32597: WordPress Video Gallery plugin <= 1.0.10 - Cross Site Scripting (XSS) vulnerability - Patchstack

Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in I Thirteen Web Solution Video Gallery plugin <= 1.0.10 versions.

CVE-2023-25019: WordPress Chaty plugin <= 3.0.9 - Cross Site Scripting (XSS) vulnerability - Patchstack

Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Premio Chaty plugin <= 3.0.9 versions

CVE-2023-32801: WordPress WooCommerce Composite Products plugin <= 8.7.5 - Reflected Cross Site Scripting (XSS) vulnerability - Patchstack

Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in WooCommerce Composite Products plugin <= 8.7.5 versions.

CVE-2023-32802: WordPress WooCommerce Pre-Orders plugin <= 1.9.0 - Cross Site Scripting (XSS) vulnerability - Patchstack

Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in WooCommerce WooCommerce Pre-Orders plugin <= 1.9.0 versions.

CVE-2023-32962: WordPress WishSuite – Wishlist for WooCommerce plugin <= 1.3.4 - Cross Site Scripting (XSS) vulnerability - Patchstack

Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in HasTheme WishSuite – Wishlist for WooCommerce plugin <= 1.3.4 versions.

CVE-2023-32742: WordPress WP SMS plugin <= 6.1.4 - Cross Site Scripting (XSS) vulnerability - Patchstack

Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in VeronaLabs WP SMS plugin <= 6.1.4 versions.

CVE-2023-32740: WordPress Custom 404 Pro plugin <= 3.8.1 - Reflected Cross Site Scripting (XSS) vulnerability - Patchstack

Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Kunal Nagar Custom 404 Pro plugin <= 3.8.1 versions.

CVE-2023-3136: MailArchiver <= 2.10.1 - Unauthenticated Stored Cross-Site Scripting via Email Subject — Wordfence Intelligence

The MailArchiver plugin for WordPress is vulnerable to Stored Cross-Site Scripting via an email subject in versions up to, and including, 2.10.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.