Security
Headlines
HeadlinesLatestCVEs

Tag

#wordpress

CVE-2023-23891: WordPress Ocean Extra plugin <= 2.1.1 - Cross Site Scripting (XSS) vulnerability - Patchstack

Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in OceanWP Ocean Extra plugin <= 2.1.1 versions. Needs the OceanWP theme installed and activated.

CVE
#xss#vulnerability#web#wordpress#auth
CVE-2023-23801: WordPress Really Simple Google Tag Manager plugin <= 1.0.6 - Cross Site Request Forgery (CSRF) vulnerability - Patchstack

Cross-Site Request Forgery (CSRF) vulnerability in HasThemes Really Simple Google Tag Manager plugin <= 1.0.6 versions.

CVE-2022-46793: WordPress Product Feed PRO for WooCommerce plugin <= 12.4.4 - Cross-Site Request Forgery (CSRF) vulnerability - Patchstack

Cross-Site Request Forgery (CSRF) vulnerability in AdTribes.Io Product Feed PRO for WooCommerce plugin <= 12.4.4 versions.

CVE-2023-24411: WordPress BNE Testimonials plugin <= 2.0.7 - Cross Site Scripting (XSS) - Patchstack

Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Kerry Kline BNE Testimonials plugin <= 2.0.7 versions.

CVE-2023-24403: WordPress bbPress Voting plugin <= 2.1.11.0 - Cross Site Scripting (XSS) vulnerability - Patchstack

Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in WP For The Win bbPress Voting plugin <= 2.1.11.0 versions.

CVE-2023-24387: WordPress WpDevArt Organization Chart plugin <= 1.4.4 - Cross Site Scripting (XSS) - Patchstack

Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in WPdevart Organization chart plugin <= 1.4.4 versions.

CVE-2023-24383: WordPress Namaste! LMS plugin <= 2.5.9.1 - Cross Site Scripting (XSS) - Patchstack

Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Kiboko Labs Namaste! LMS plugin <= 2.5.9.1 versions.

CVE-2023-23898: WordPress Blocksy Companion plugin <= 1.8.67 - Cross Site Scripting (XSS) vulnerability - Patchstack

Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in CreativeThemes Blocksy Companion plugin <= 1.8.67 versions.

CVE-2023-24002: WordPress YouTube Embed, Playlist and Popup by WpDevArt plugin <= 2.6.3 - Cross Site Scripting (XSS) - Patchstack

Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in WPdevart YouTube Embed, Playlist and Popup by WpDevArt plugin <= 2.6.3 versions.

CVE-2023-24003: WordPress WP Popups – WordPress Popup builder plugin <= 2.1.4.8 - Cross Site Scripting (XSS) - Patchstack

Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Timersys WP Popups – WordPress Popup plugin <= 2.1.4.8 versions.