Security
Headlines
HeadlinesLatestCVEs

Tag

#wordpress

CVE-2023-33211: WordPress WP-Matomo Integration (WP-Piwik) plugin <= 1.0.27 - Cross Site Scripting (XSS) vulnerability - Patchstack

Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in André Bräkling WP-Matomo Integration (WP-Piwik) plugin <= 1.0.27 versions.

CVE
#xss#vulnerability#web#wordpress#auth#ssh
CVE-2023-32800: WordPress Rank Math SEO PRO plugin <= 3.0.35 - Reflected Cross Site Scripting (XSS) vulnerability - Patchstack

Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in One Rank Math SEO PRO plugin <= 3.0.35 versions.

CVE-2023-28785: WordPress Yoast SEO: Local plugin <= 14.9 - Cross Site Scripting (XSS) vulnerability - Patchstack

Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Yoast Yoast SEO: Local plugin <= 14.9 versions.

CVE-2023-33316: WordPress WooCommerce Follow-Up Emails plugin <= 4.9.40 - Multiple Cross Site Request Forgery (CSRF) vulnerability - Patchstack

Cross-Site Request Forgery (CSRF) vulnerability in WooCommerce WooCommerce Follow-Up Emails (AutomateWoo) plugin <= 4.9.40 versions.

CVE-2023-33313: WordPress WIP Custom Login plugin <= 1.2.9 - Cross Site Request Forgery (CSRF) vulnerability - Patchstack

Cross-Site Request Forgery (CSRF) vulnerability in ThemeinProgress WIP Custom Login plugin <= 1.2.9 versions.

CVE-2023-33319: WordPress WooCommerce Follow-Up Emails plugin <= 4.9.40 - Reflected Cross Site Scripting (XSS) vulnerability - Patchstack

Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in WooCommerce WooCommerce Follow-Up Emails (AutomateWoo) plugin <= 4.9.40 versions.

CVE-2023-33332: WordPress WooCommerce Product Vendors plugin <= 2.1.76 - Reflected Cross Site Scripting (XSS) vulnerability - Patchstack

Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in WooCommerce Product Vendors plugin <= 2.1.76 versions.

CVE-2023-33311: WordPress Contact Form Entries plugin <= 1.3.0 - Cross Site Scripting (XSS) vulnerability - Patchstack

Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in CRM Perks Contact Form Entries plugin <= 1.3.0 versions.

CVE-2023-33328: WordPress PluginOps Optin Builder plugin <= 4.0.9.1 - Cross Site Scripting (XSS) - Patchstack

Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in PluginOps MailChimp Subscribe Form plugin <= 4.0.9.1 versions.

CVE-2023-33931: WordPress YouTube Playlist Player plugin <= 4.6.4 - Cross Site Request Forgery (CSRF) vulnerability - Patchstack

Cross-Site Request Forgery (CSRF) vulnerability in Ciprian Popescu YouTube Playlist Player plugin <= 4.6.4 versions.