CVE-2023-50368 – WordPress Shortcodes and extra features for Phlox theme Plugin <= 2.15.2 is vulnerable to Cross Site Scripting (XSS)
https://notcve.org/view.php?id=CVE-2023-50368
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Averta Shortcodes and extra features for Phlox theme allows Stored XSS.This issue affects Shortcodes and extra features for Phlox theme: from n/a through 2.15.2. La vulnerabilidad de neutralización inadecuada de la entrada durante la generación de páginas web ('Cross-site Scripting') en Averta Shortcodes and extra features for Phlox theme permite almacenar XSS. Este problema afecta a Shortcodes and extra features for Phlox theme: desde n/a hasta 2.15.2. The Shortcodes and extra features for Phlox theme plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in all versions up to, and including, 2.15.4 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. • https://patchstack.com/database/vulnerability/auxin-elements/wordpress-shortcodes-and-extra-features-for-phlox-theme-plugin-2-15-2-cross-site-scripting-xss-vulnerability?_s_id=cve • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •
CVE-2023-47507 – WordPress Master Slider Pro Plugin <= 3.6.5 is vulnerable to PHP Object Injection
https://notcve.org/view.php?id=CVE-2023-47507
Deserialization of Untrusted Data vulnerability in Master Slider Master Slider Pro.This issue affects Master Slider Pro: from n/a through 3.6.5. Vulnerabilidad de deserialización de datos no confiables en Master Slider Master Slider Pro. Este problema afecta a Master Slider Pro: desde n/a hasta 3.6.5. The Master Slider Pro plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 3.6.5 via deserialization of untrusted input. This makes it possible for unauthenticated attackers to inject a PHP Object. • https://patchstack.com/database/vulnerability/masterslider/wordpress-master-slider-pro-plugin-3-6-5-php-object-injection-vulnerability?_s_id=cve • CWE-502: Deserialization of Untrusted Data •
CVE-2023-47508 – WordPress Master Slider Pro Plugin <= 3.6.5 is vulnerable to Cross Site Scripting (XSS)
https://notcve.org/view.php?id=CVE-2023-47508
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Averta Master Slider Pro plugin <= 3.6.5 versions. Vulnerabilidad de Cross-Site Scripting (XSS) Reflejada No Autenticada en el complemento Averta Master Slider Pro en versiones <=3.6.5. The Master Slider Pro plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via an unknown parameter in versions up to, and including, 3.6.5 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link. • https://patchstack.com/database/vulnerability/masterslider/wordpress-master-slider-pro-plugin-3-6-5-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •
CVE-2022-3359 – Shortcodes and extra features for Phlox theme < 2.10.7 - PHP Objection Injection
https://notcve.org/view.php?id=CVE-2022-3359
The Shortcodes and extra features for Phlox theme WordPress plugin before 2.10.7 unserializes the content of an imported file, which could lead to PHP object injection when a user imports (intentionally or not) a malicious file and a suitable gadget chain is present on the blog. El complemento de WordPress Shortcodes and extra features para el tema Phlox anterior a 2.10.7 deserializa el contenido de un archivo importado, lo que podría provocar la inyección de objetos PHP cuando un usuario importa (intencionalmente o no) un archivo malicioso y una cadena de gadgets adecuada está presente en el Blog. The 'Shortcodes and extra features for Phlox theme' plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 2.10.5 via deserialization of untrusted input in the auxin_customizer_export function. This allows attackers to inject a PHP Object. No POP chain is present in the vulnerable plugin. • https://wpscan.com/vulnerability/08f3ce22-94a0-496a-aaf9-d35b6b0f5bb6 • CWE-502: Deserialization of Untrusted Data •
CVE-2022-1910 – Shortcodes and extra features for Phlox theme < 2.9.8 - Reflected Cross-Site-Scripting
https://notcve.org/view.php?id=CVE-2022-1910
The Shortcodes and extra features for Phlox WordPress plugin before 2.9.8 does not sanitise and escape a parameter before outputting it back in the response, leading to a Reflected Cross-Site Scripting El plugin Shortcodes and extra features for Phlox WordPress anterior a la versión 2.9.8 no sanea y escapa de un parámetro antes de devolverlo a la respuesta, lo que lleva a un Reflected Cross-Site Scripting The Shortcodes and extra features for Phlox WordPress plugin before 2.9.8 does not sanitise and escape a parameter before outputting it back in the response, leading to a Reflected Cross-Site Scripting • https://wpscan.com/vulnerability/8afe1638-66fa-44c7-9d02-c81573193b47 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •