Illi Link Party
by WordPress
CVEs (4)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2023-7231 | 0.00 | — | 0.00 | May 15, 2025 | The illi Link Party! WordPress plugin through 1.0 lacks proper access controls, allowing unauthenticated visitors to delete links. | |||
| CVE-2023-7230 | 0.00 | — | 0.00 | May 15, 2025 | The illi Link Party! WordPress plugin through 1.0 does not sanitize and escape some parameters, which could allow users with a role as low as admin to perform Cross-Site Scripting attacks. | |||
| CVE-2023-7229 | 0.00 | — | 0.00 | May 15, 2025 | The illi Link Party! WordPress plugin through 1.0 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack. | |||
| CVE-2023-7228 | 0.00 | — | 0.00 | May 15, 2025 | The illi Link Party! WordPress plugin through 1.0 does not sanitise and escape some parameters, which could allow unauthenticated vistors to perform Cross-Site Scripting attacks. |
- CVE-2023-7231May 15, 2025risk 0.00cvss —epss 0.00
The illi Link Party! WordPress plugin through 1.0 lacks proper access controls, allowing unauthenticated visitors to delete links.
- CVE-2023-7230May 15, 2025risk 0.00cvss —epss 0.00
The illi Link Party! WordPress plugin through 1.0 does not sanitize and escape some parameters, which could allow users with a role as low as admin to perform Cross-Site Scripting attacks.
- CVE-2023-7229May 15, 2025risk 0.00cvss —epss 0.00
The illi Link Party! WordPress plugin through 1.0 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack.
- CVE-2023-7228May 15, 2025risk 0.00cvss —epss 0.00
The illi Link Party! WordPress plugin through 1.0 does not sanitise and escape some parameters, which could allow unauthenticated vistors to perform Cross-Site Scripting attacks.