VYPR

Rafflepress

by Rafflepress

CVEs (2)

  • CVE-2024-1935HigMar 13, 2024
    risk 0.47cvss 7.2epss 0.01

    The Giveaways and Contests by RafflePress – Get More Website Traffic, Email Subscribers, and Social Followers plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘parent_url’ parameter in all versions up to, and including, 1.12.5 due to insufficient…

  • CVE-2024-3963MedJul 13, 2024
    risk 0.42cvss 6.5epss 0.00

    The Giveaways and Contests by RafflePress WordPress plugin before 1.12.14 does not sanitise and escape some parameters, which could allow users with a role as low as editor to perform Cross-Site Scripting attacks