VYPR

Quotes And Tips

by Bestwebsoft

CVEs (3)

  • CVE-2015-9385MedSep 20, 2019
    risk 0.40cvss 6.1epss 0.01

    The quotes-and-tips plugin before 1.20 for WordPress has XSS.

  • CVE-2017-2171MedMay 22, 2017
    risk 0.40cvss 6.1epss 0.01

    Cross-site scripting vulnerability in Captcha prior to version 4.3.0, Car Rental prior to version 1.0.5, Contact Form Multi prior to version 1.2.1, Contact Form prior to version 4.0.6, Contact Form to DB prior to version 1.5.7, Custom Admin Page prior to version 0.1.2, Custom…

  • CVE-2024-3112MedJul 12, 2024
    risk 0.31cvss 4.8epss 0.00

    The Quotes and Tips by BestWebSoft WordPress plugin before 1.45 does not properly validate image files uploaded, allowing high privilege users such as admin to upload arbitrary files on the server even when they should not be allowed to (for example in multisite setup)