VYPR

Wp Datepicker

by Androidbubbles

CVEs (4)

  • CVE-2024-3895HigMay 2, 2024
    risk 0.50cvss 8.8epss 0.01

    The WP Datepicker plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the wpdp_add_new_datepicker_ajax() function in all versions up to, and including, 2.1.0. This makes it possible for authenticated attackers, with …

  • CVE-2024-47321MedNov 1, 2024
    risk 0.42cvss 6.5epss 0.00

    Missing Authorization vulnerability in Fahad Mahmood WP Datepicker wp-datepicker.This issue affects WP Datepicker: from n/a through <= 2.1.1.

  • CVE-2024-12468MedDec 24, 2024
    risk 0.40cvss 6.1epss 0.00

    The WP Datepicker plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'wpdp_get_selected_datepicker' parameter in all versions up to, and including, 2.1.4 due to insufficient input sanitization and output escaping. This makes it possible for…

  • CVE-2024-44042MedOct 6, 2024
    risk 0.38cvss 5.9epss 0.00

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Fahad Mahmood WP Datepicker wp-datepicker allows Stored XSS.This issue affects WP Datepicker: from n/a through <= 2.1.1.