VYPR
Vendor

Fahadmahmood

Products
5
CVEs
7
Across products
7
Status
Private

Products

5

Recent CVEs

7
  • CVE-2024-10057MedOct 18, 2024
    risk 0.42cvss 6.4epss 0.00

    The RSS Feed Widget plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's rfw-youtube-videos shortcode in all versions up to, and including, 2.9.9 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it…

  • CVE-2024-35695MedJun 8, 2024
    risk 0.42cvss 6.5epss 0.00

    Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Fahad Mahmood WP Docs allows Stored XSS.This issue affects WP Docs: from n/a through 2.1.3.

  • CVE-2025-8046MedAug 14, 2025
    risk 0.40cvss 6.1epss 0.00

    The Injection Guard WordPress plugin before 1.2.8 does not escape the $_SERVER['REQUEST_URI'] parameter before outputting it back in an attribute, which could lead to Reflected Cross-Site Scripting in old web browsers

  • CVE-2025-7808MedAug 14, 2025
    risk 0.40cvss 6.1epss 0.00

    The WP Shopify WordPress plugin before 1.5.4 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

  • CVE-2024-12468MedDec 24, 2024
    risk 0.40cvss 6.1epss 0.00

    The WP Datepicker plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'wpdp_get_selected_datepicker' parameter in all versions up to, and including, 2.1.4 due to insufficient input sanitization and output escaping. This makes it possible for…

  • CVE-2024-12635MedDec 21, 2024
    risk 0.35cvss 6.5epss 0.00

    The WP Docs plugin for WordPress is vulnerable to time-based SQL Injection via the 'dir_id' parameter in all versions up to, and including, 2.2.0 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes…

  • CVE-2024-9835MedNov 12, 2024
    risk 0.31cvss 4.8epss 0.00

    The RSS Feed Widget WordPress plugin before 3.0.1 does not escape the $_SERVER['REQUEST_URI'] parameter before outputting it back in an attribute, which could lead to Reflected Cross-Site Scripting in old web browsers