Page 5 of 25 results (0.006 seconds)

CVSS: 9.8EPSS: 0%CPEs: 1EXPL: 0

Deserialization of Untrusted Data vulnerability in Master Slider Master Slider Pro.This issue affects Master Slider Pro: from n/a through 3.6.5. Vulnerabilidad de deserialización de datos no confiables en Master Slider Master Slider Pro. Este problema afecta a Master Slider Pro: desde n/a hasta 3.6.5. The Master Slider Pro plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 3.6.5 via deserialization of untrusted input. This makes it possible for unauthenticated attackers to inject a PHP Object. • https://patchstack.com/database/vulnerability/masterslider/wordpress-master-slider-pro-plugin-3-6-5-php-object-injection-vulnerability?_s_id=cve • CWE-502: Deserialization of Untrusted Data •

CVSS: 7.1EPSS: 0%CPEs: 1EXPL: 0

Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Averta Master Slider Pro plugin <= 3.6.5 versions. Vulnerabilidad de Cross-Site Scripting (XSS) Reflejada No Autenticada en el complemento Averta Master Slider Pro en versiones &lt;=3.6.5. The Master Slider Pro plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via an unknown parameter in versions up to, and including, 3.6.5 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link. • https://patchstack.com/database/vulnerability/masterslider/wordpress-master-slider-pro-plugin-3-6-5-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVSS: 8.8EPSS: 0%CPEs: 1EXPL: 1

The Shortcodes and extra features for Phlox theme WordPress plugin before 2.10.7 unserializes the content of an imported file, which could lead to PHP object injection when a user imports (intentionally or not) a malicious file and a suitable gadget chain is present on the blog. El complemento de WordPress Shortcodes and extra features para el tema Phlox anterior a 2.10.7 deserializa el contenido de un archivo importado, lo que podría provocar la inyección de objetos PHP cuando un usuario importa (intencionalmente o no) un archivo malicioso y una cadena de gadgets adecuada está presente en el Blog. The 'Shortcodes and extra features for Phlox theme' plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 2.10.5 via deserialization of untrusted input in the auxin_customizer_export function. This allows attackers to inject a PHP Object. No POP chain is present in the vulnerable plugin. • https://wpscan.com/vulnerability/08f3ce22-94a0-496a-aaf9-d35b6b0f5bb6 • CWE-502: Deserialization of Untrusted Data •

CVSS: 6.1EPSS: 0%CPEs: 1EXPL: 1

The Shortcodes and extra features for Phlox WordPress plugin before 2.9.8 does not sanitise and escape a parameter before outputting it back in the response, leading to a Reflected Cross-Site Scripting El plugin Shortcodes and extra features for Phlox WordPress anterior a la versión 2.9.8 no sanea y escapa de un parámetro antes de devolverlo a la respuesta, lo que lleva a un Reflected Cross-Site Scripting The Shortcodes and extra features for Phlox WordPress plugin before 2.9.8 does not sanitise and escape a parameter before outputting it back in the response, leading to a Reflected Cross-Site Scripting • https://wpscan.com/vulnerability/8afe1638-66fa-44c7-9d02-c81573193b47 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVSS: 5.4EPSS: 0%CPEs: 2EXPL: 1

The Master Slider plugin 3.2.7 and 3.5.1 for WordPress has XSS via the wp-admin/admin-ajax.php Name input field of the MSPanel.Settings value on Callback. El plugin Master Slider, en versiones 3.2.7 y 3.5.1 para WordPress, tiene Cross-Site Scripting (XSS) mediante el campo de entrada Name en wp-admin/admin-ajax.php del valor MSPanel.Settings en Callback. The Master Slider plugin for WordPress has XSS via the wp-admin/admin-ajax.php Name input field of the MSPanel.Settings value on Callback. • https://www.vulnerability-lab.com/get_content.php?id=2158 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •