VYPR

WOOF WordPress plugin

by WordPress

CVEs (11)

  • CVE-2022-3900CriDec 12, 2022
    risk 0.65cvss 9.8epss 0.19

    The Cooked Pro WordPress plugin before 1.7.5.7 does not properly validate or sanitize the recipe_args parameter before unserializing it in the cooked_loadmore action, allowing an unauthenticated attacker to trigger a PHP Object injection vulnerability.

  • CVE-2021-24384CriJul 6, 2021
    risk 0.64cvss 9.8epss 0.02

    The joomsport_md_load AJAX action of the JoomSport WordPress plugin before 5.1.8, registered for both unauthenticated and unauthenticated users, unserialised user input from the shattr POST parameter, leading to a PHP Object Injection issue. Even though the plugin does not have…

  • CVE-2021-24336HigJun 7, 2021
    risk 0.47cvss 7.2epss 0.02

    The FlightLog WordPress plugin through 3.0.2 does not sanitise, validate or escape various POST parameters before using them a SQL statement, leading to SQL injections exploitable by editor and administrator users

  • CVE-2022-1269MedMay 2, 2022
    risk 0.40cvss 6.1epss 0.01

    The Fast Flow WordPress plugin before 1.2.12 does not sanitise and escape the page parameter before outputting back in an attribute in an admin dashboard, leading to a Reflected Cross-Site Scripting

  • CVE-2021-25071MedMar 28, 2022
    risk 0.40cvss 6.1epss 0.01

    The WordPress plugin through 2.0.1 does not sanitise and escape the translation parameter before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting

  • CVE-2021-25085MedFeb 1, 2022
    risk 0.40cvss 6.1epss 0.02

    The WOOF WordPress plugin before 1.2.6.3 does not sanitise and escape the woof_redraw_elements before outputing back in an admin page, leading to a Reflected Cross-Site Scripting

  • CVE-2022-0898MedMay 9, 2022
    risk 0.35cvss 5.4epss 0.01

    The IgniteUp WordPress plugin through 3.4.1 does not sanitise and escape some fields when high privilege users don't have the unfiltered_html capability, which could lead to Stored Cross-Site Scripting issues

  • CVE-2022-0376MedMay 30, 2022
    risk 0.31cvss 4.8epss 0.01

    The User Meta WordPress plugin before 2.4.3 does not sanitise and escape the Form Name, as well as Shared Field Labels before outputting them in the admin dashboard when editing a form, which could allow high privilege users to perform Cross-Site Scripting attacks even when…

  • CVE-2022-0703MedMar 14, 2022
    risk 0.31cvss 4.8epss 0.01

    The GD Mylist WordPress plugin through 1.1.1 does not sanitise and escape some of its settings, allowing high privilege users such as admin to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed

  • CVE-2021-24343MedJun 7, 2021
    risk 0.31cvss 4.8epss 0.01

    The iFlyChat WordPress plugin before 4.7.0 does not sanitise its APP ID setting before outputting it back in the page, leading to an authenticated Stored Cross-Site Scripting issue

  • CVE-2021-24806MedNov 8, 2021
    risk 0.28cvss 4.3epss 0.00

    The wpDiscuz WordPress plugin before 7.3.4 does check for CSRF when adding, editing and deleting comments, which could allow attacker to make logged in users such as admin edit and delete arbitrary comment, or the user who made the comment to edit it via a CSRF attack. Attackers…