Never5
Products
3- 6 CVEs
- 2 CVEs
- 1 CVE
Recent CVEs
9| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2015-9362 | Med | 0.40 | 6.1 | 0.01 | Aug 28, 2019 | The Post Connector plugin before 1.0.4 for WordPress has XSS via add_query_arg() and remove_query_arg(). | ||
| CVE-2015-9361 | Med | 0.40 | 6.1 | 0.01 | Aug 28, 2019 | The Related Posts plugin before 1.8.2 for WordPress has XSS via add_query_arg() and remove_query_arg(). | ||
| CVE-2015-9296 | Med | 0.40 | 6.1 | 0.01 | Aug 13, 2019 | The download-monitor plugin before 1.7.1 for WordPress has XSS related to add_query_arg. | ||
| CVE-2023-28931 | Med | 0.38 | 5.9 | 0.00 | Aug 8, 2023 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Never5 Post Connector plugin <= 1.0.9 versions. | ||
| CVE-2021-24180 | Med | 0.35 | 5.4 | 0.01 | Apr 5, 2021 | Unvalidated input and lack of output encoding within the Related Posts for WordPress plugin before 2.0.4 lead to a Reflected Cross-Site Scripting (XSS) vulnerability within the 'lang' GET parameter while editing a post, triggered when users with the capability of editing posts… | ||
| CVE-2021-24482 | Med | 0.31 | 4.8 | 0.01 | Jul 19, 2021 | The Related Posts for WordPress plugin through 2.0.4 does not sanitise its heading_text and CSS settings, allowing high privilege users (admin) to set XSS payloads in them, leading to Stored Cross-Site Scripting issues. | ||
| CVE-2024-0592 | Med | 0.28 | 5.4 | 0.00 | Mar 13, 2024 | The Related Posts for WordPress plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.2.1. This is due to missing or incorrect nonce validation on the handle_create_link() function. This makes it possible for unauthenticated… | ||
| CVE-2022-3506 | Med | 0.00 | 5.4 | 0.01 | Oct 14, 2022 | Cross-site Scripting (XSS) - Stored in GitHub repository barrykooij/related-posts-for-wp prior to 2.1.3. | ||
| CVE-2013-3257 | 0.00 | — | 0.01 | Jun 2, 2014 | Cross-site request forgery (CSRF) vulnerability in the Related Posts plugin before 2.7.2 for WordPress allows remote attackers to hijack the authentication of users for requests that modify settings via unspecified vectors. |
- risk 0.40cvss 6.1epss 0.01
The Post Connector plugin before 1.0.4 for WordPress has XSS via add_query_arg() and remove_query_arg().
- risk 0.40cvss 6.1epss 0.01
The Related Posts plugin before 1.8.2 for WordPress has XSS via add_query_arg() and remove_query_arg().
- risk 0.40cvss 6.1epss 0.01
The download-monitor plugin before 1.7.1 for WordPress has XSS related to add_query_arg.
- risk 0.38cvss 5.9epss 0.00
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Never5 Post Connector plugin <= 1.0.9 versions.
- risk 0.35cvss 5.4epss 0.01
Unvalidated input and lack of output encoding within the Related Posts for WordPress plugin before 2.0.4 lead to a Reflected Cross-Site Scripting (XSS) vulnerability within the 'lang' GET parameter while editing a post, triggered when users with the capability of editing posts…
- risk 0.31cvss 4.8epss 0.01
The Related Posts for WordPress plugin through 2.0.4 does not sanitise its heading_text and CSS settings, allowing high privilege users (admin) to set XSS payloads in them, leading to Stored Cross-Site Scripting issues.
- risk 0.28cvss 5.4epss 0.00
The Related Posts for WordPress plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.2.1. This is due to missing or incorrect nonce validation on the handle_create_link() function. This makes it possible for unauthenticated…
- risk 0.00cvss 5.4epss 0.01
Cross-site Scripting (XSS) - Stored in GitHub repository barrykooij/related-posts-for-wp prior to 2.1.3.
- CVE-2013-3257Jun 2, 2014risk 0.00cvss —epss 0.01
Cross-site request forgery (CSRF) vulnerability in the Related Posts plugin before 2.7.2 for WordPress allows remote attackers to hijack the authentication of users for requests that modify settings via unspecified vectors.