Security
Headlines
HeadlinesLatestCVEs

Tag

#wordpress

CVE-2023-36384: WordPress Booking Calendar Contact Form plugin <= 1.2.40 - Cross Site Scripting (XSS) - Patchstack

Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in CodePeople Booking Calendar Contact Form plugin <= 1.2.40 versions.

CVE
#xss#vulnerability#web#wordpress#auth
CVE-2023-36383: WordPress Event Manager and Tickets Selling Plugin for WooCommerce plugin <= 3.9.5 - Cross Site Scripting (XSS) vulnerability - Patchstack

Auth. (editor+) Stored Cross-Site Scripting (XSS) vulnerability in MagePeople Team Event Manager and Tickets Selling Plugin for WooCommerce plugin <= 3.9.5 versions.

CVE-2023-24390: WordPress WeSecur Security plugin <= 1.2.1 - Cross Site Scripting (XSS) vulnerability - Patchstack

Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in WeSecur Security plugin <= 1.2.1 versions.

CVE-2022-47421: WordPress ARMember plugin <= 4.0.4 - Stored Cross Site Scripting (XSS) on Common Messages Settings - Patchstack

Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Repute InfoSystems ARMember (free), Repute InfoSystems ARMember (premium) plugins.

CVE-2023-32965: WordPress Jazz Popups plugin <= 1.8.7 - Cross Site Scripting (XSS) vulnerability - Patchstack

Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in CRUDLab Jazz Popups plugin <= 1.8.7 versions.

CVE-2022-34155: WordPress OAuth Single Sign On – SSO (OAuth Client) plugin <= 6.23.3 - Broken Authentication vulnerability - Patchstack

Improper Authentication vulnerability in miniOrange OAuth Single Sign On – SSO (OAuth Client) plugin allows Authentication Bypass.This issue affects OAuth Single Sign On – SSO (OAuth Client): from n/a through 6.23.3.

CVE-2023-25036: WordPress Social Media Icons Widget plugin <= 1.6 - Cross Site Request Forgery (CSRF) vulnerability - Patchstack

Cross-Site Request Forgery (CSRF) vulnerability in akhlesh-nagar, a.Ankit Social Media Icons Widget plugin <= 1.6 versions.

CVE-2023-23660: WordPress MainWP Maintenance Extension Plugin <= 4.1.1 - Subscriber+ SQL Injection Vulnerability - Patchstack

Auth. (subscriber+) SQL Injection (SQLi) vulnerability in MainWP MainWP Maintenance Extension plugin <= 4.1.1 versions.

CVE-2023-37973: WordPress Replace Word plugin <= 2.1 - Cross Site Request Forgery (CSRF) vulnerability - Patchstack

Cross-Site Request Forgery (CSRF) vulnerability in David Pokorny Replace Word plugin <= 2.1 versions.