Security
Headlines
HeadlinesLatestCVEs

Tag

#wordpress

CVE-2023-34017: WordPress Five Star Restaurant Reservations plugin <= 2.6.7 - Reflected Cross Site Scripting (XSS) vulnerability - Patchstack

Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in FiveStarPlugins Five Star Restaurant Reservations plugin <= 2.6.7 versions.

CVE
#xss#vulnerability#web#wordpress#auth
CVE-2023-36503: WordPress WordPress Button Plugin MaxButtons plugin <= 9.5.3 - Cross Site Scripting (XSS) vulnerability - Patchstack

Auth. (contributor+) Cross-Site Scripting (XSS) vulnerability in Max Foundry WordPress Button Plugin MaxButtons plugin <= 9.5.3 versions.

CVE-2023-36385: WordPress PostX – Gutenberg Post Grid Blocks plugin <= 2.9.9 - Cross Site Scripting (XSS) vulnerability - Patchstack

Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in wpxpo PostX – Gutenberg Post Grid Blocks plugin <= 2.9.9 versions.

CVE-2023-36502: WordPress Balkon theme <= 1.3.2 - Reflected Cross Site Scripting (XSS) vulnerability - Patchstack

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in cththemes Balkon plugin <= 1.3.2 versions.

CVE-2023-34369: WordPress Login Configurator plugin <= 2.1 - Cross Site Scripting (XSS) vulnerability - Patchstack

Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in GrandSlambert Login Configurator plugin <= 2.1 versions.

CVE-2023-36501: WordPress teachPress plugin <= 9.0.2 - Cross Site Scripting (XSS) vulnerability - Patchstack

Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Michael Winkler teachPress plugin <= 9.0.2 versions.

WordPress Page Builder KingComposer 2.8.1 Cross Site Scripting

WordPress Page Builder KingComposer plugin version 2.8.1 suffers from a cross site scripting vulnerability.

WordPress Duplicator 3.8.7 Backup Disclosure

WordPress Duplicator plugin version 3.8.7 appears to leave backups in a world accessible directory under the document root.

CVE-2023-35043: WordPress Recent Posts Slider plugin <= 1.1 - Cross Site Scripting (XSS) vulnerability - Patchstack

Unauth. Stored Cross-Site Scripting (XSS) vulnerability in Neha Goel Recent Posts Slider plugin <= 1.1 versions.