VYPR

Juicer

by WordPress

CVEs (2)

  • CVE-2026-53737MedJun 10, 2026
    risk 0.40cvss 6.1epss

    Juicer through 1.12.18 fails to escape remote feed API response fields before rendering them on the admin settings page. Attackers controlling the connected feed data can inject script that executes in an administrator's browser when the settings page loads.

  • CVE-2023-0172Mar 13, 2023
    risk 0.00cvss epss 0.00

    The Juicer WordPress plugin before 1.11 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting…