Security
Headlines
HeadlinesLatestCVEs

Tag

#xss

CVE-2023-33211: WordPress WP-Matomo Integration (WP-Piwik) plugin <= 1.0.27 - Cross Site Scripting (XSS) vulnerability - Patchstack

Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in André Bräkling WP-Matomo Integration (WP-Piwik) plugin <= 1.0.27 versions.

CVE
#xss#vulnerability#web#wordpress#auth#ssh
CVE-2023-32800: WordPress Rank Math SEO PRO plugin <= 3.0.35 - Reflected Cross Site Scripting (XSS) vulnerability - Patchstack

Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in One Rank Math SEO PRO plugin <= 3.0.35 versions.

CVE-2023-28785: WordPress Yoast SEO: Local plugin <= 14.9 - Cross Site Scripting (XSS) vulnerability - Patchstack

Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Yoast Yoast SEO: Local plugin <= 14.9 versions.

CVE-2023-33319: WordPress WooCommerce Follow-Up Emails plugin <= 4.9.40 - Reflected Cross Site Scripting (XSS) vulnerability - Patchstack

Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in WooCommerce WooCommerce Follow-Up Emails (AutomateWoo) plugin <= 4.9.40 versions.

CVE-2023-33332: WordPress WooCommerce Product Vendors plugin <= 2.1.76 - Reflected Cross Site Scripting (XSS) vulnerability - Patchstack

Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in WooCommerce Product Vendors plugin <= 2.1.76 versions.

CVE-2023-33311: WordPress Contact Form Entries plugin <= 1.3.0 - Cross Site Scripting (XSS) vulnerability - Patchstack

Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in CRM Perks Contact Form Entries plugin <= 1.3.0 versions.

CVE-2023-33328: WordPress PluginOps Optin Builder plugin <= 4.0.9.1 - Cross Site Scripting (XSS) - Patchstack

Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in PluginOps MailChimp Subscribe Form plugin <= 4.0.9.1 versions.

CVE-2023-33309: WordPress Duplicator Pro plugin <= 4.5.11 - Reflected Cross Site Scripting (XSS) vulnerability - Patchstack

Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Awesome Motive Duplicator Pro plugin <= 4.5.11 versions.

CVE-2023-33326: WordPress EventPrime plugin <= 2.8.6 - Reflected Cross Site Scripting (XSS) - Patchstack

Unauth. Reflected (XSS) Cross-Site Scripting (XSS) vulnerability in EventPrime plugin <= 2.8.6 versions.

CVE-2023-32958: WordPress Novelist plugin <= 1.2.0 - Cross Site Scripting (XSS) vulnerability - Patchstack

Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Nose Graze Novelist plugin <= 1.2.0 versions.