CVE-2023-23673 – WordPress I Recommend This Plugin <= 3.8.3 is vulnerable to Cross Site Scripting (XSS)
https://notcve.org/view.php?id=CVE-2023-23673
19 Apr 2023 — Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Harish Chouhan, Themeist I Recommend This plugin <= 3.8.3 versions. The I Recommend This plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versions up to, and including, 3.8.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a us... • https://patchstack.com/database/vulnerability/i-recommend-this/wordpress-i-recommend-this-plugin-3-8-3-cross-site-scripting-xss-vulnerability?_s_id=cve • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •
CVE-2023-28696 – WordPress I Recommend This Plugin <= 3.9.0 is vulnerable to Cross Site Request Forgery (CSRF)
https://notcve.org/view.php?id=CVE-2023-28696
22 Mar 2023 — Cross-Site Request Forgery (CSRF) vulnerability in Harish Chouhan, Themeist I Recommend This allows Cross Site Request Forgery.This issue affects I Recommend This: from n/a through 3.9.0. Vulnerabilidad de Cross-Site Request Forgery (CSRF) en el complemento Harish Chouhan, Themeist I Recommend en versiones <= 3.9.0. The I Recommend This plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.9.0. This is due to missing nonce validation on the ajax_callback fun... • https://patchstack.com/database/vulnerability/i-recommend-this/wordpress-i-recommend-this-plugin-3-8-3-cross-site-request-forgery-csrf?_s_id=cve • CWE-352: Cross-Site Request Forgery (CSRF) •
CVE-2014-10376 – I Recommend This < 3.7.3 - SQL Injection
https://notcve.org/view.php?id=CVE-2014-10376
24 Sep 2014 — The i-recommend-this plugin before 3.7.3 for WordPress has SQL injection. El plugin i-recomendar-this versiones anteriores a 3.7.3 para WordPress, presenta una inyección SQL. • https://wordpress.org/plugins/i-recommend-this/#developers • CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') •
CVE-2014-125099 – I Recommend This Plugin dot-irecommendthis.php sql injection
https://notcve.org/view.php?id=CVE-2014-125099
24 Sep 2014 — A vulnerability has been found in I Recommend This Plugin up to 3.7.2 on WordPress and classified as critical. Affected by this vulnerability is an unknown functionality of the file dot-irecommendthis.php. The manipulation leads to sql injection. The attack can be launched remotely. Upgrading to version 3.7.3 is able to address this issue. • https://github.com/wp-plugins/i-recommend-this/commit/058b3ef5c7577bf557557904a53ecc8599b13649 • CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') •