VYPR
Vendor

Essentialplugin

Products
7
CVEs
9
Across products
9
Status
Private

Products

7

Recent CVEs

9
  • CVE-2024-4194MedJun 6, 2024
    risk 0.42cvss 6.5epss 0.00

    The The Album and Image Gallery plus Lightbox plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 2.0. This is due to the software allowing users to execute an action that does not properly validate a value before running…

  • CVE-2023-38516MedSep 3, 2023
    risk 0.42cvss 6.5epss 0.00

    Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in WP OnlineSupport, Essential Plugin Audio Player with Playlist Ultimate plugin <= 1.2.2 versions.

  • CVE-2022-45818MedMay 4, 2023
    risk 0.42cvss 6.5epss 0.00

    Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in WP OnlineSupport, Essential Plugin Hero Banner Ultimate plugin <= 1.3.4 versions.

  • CVE-2022-2115MedJul 25, 2022
    risk 0.40cvss 6.1epss 0.01

    The Popup Anything WordPress plugin before 2.1.7 does not sanitise and escape a parameter before outputting it back in a frontend page, leading to a Reflected Cross-Site Scripting

  • CVE-2022-4791MedFeb 21, 2023
    risk 0.35cvss 5.4epss 0.00

    The Product Slider and Carousel with Category for WooCommerce WordPress plugin before 2.8 does not validate and escape one of its shortcode attributes, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attack.

  • CVE-2022-4824MedFeb 6, 2023
    risk 0.35cvss 5.4epss 0.01

    The WP Blog and Widgets WordPress plugin before 2.3.1 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be…

  • CVE-2022-4747MedFeb 6, 2023
    risk 0.35cvss 5.4epss 0.01

    The Post Category Image With Grid and Slider WordPress plugin before 1.4.8 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting…

  • CVE-2021-24883MedNov 29, 2021
    risk 0.35cvss 5.4epss 0.01

    The Popup Anything WordPress plugin before 2.0.4 does not escape the Link Text and Button Text fields of Popup, which could allow users with a role as low as Contributor to perform Cross-Site Scripting attacks

  • CVE-2022-38077MedMar 29, 2023
    risk 0.28cvss 4.3epss 0.00

    Cross-Site Request Forgery (CSRF) vulnerability in WP OnlineSupport, Essential Plugin Popup Anything – A Marketing Popup and Lead Generation Conversions plugin <= 2.2.1 versions.