CVE-2024-22291 – WordPress Browser Theme Color Plugin <= 1.3 is vulnerable to Cross Site Request Forgery (CSRF)
https://notcve.org/view.php?id=CVE-2024-22291
17 Jan 2024 — Cross-Site Request Forgery (CSRF) vulnerability in Marco Milesi Browser Theme Color.This issue affects Browser Theme Color: from n/a through 1.3. Vulnerabilidad de Cross-Site Request Forgery (CSRF) en Marco Milesi Browser Theme Color. Este problema afecta a Browser Theme Color: desde n/a hasta 1.3. The Browser Theme Color plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.3. This is due to missing or incorrect nonce validation on the 'btc_settings_page' func... • https://patchstack.com/database/vulnerability/browser-theme-color/wordpress-browser-theme-color-plugin-1-3-cross-site-request-forgery-csrf-vulnerability?_s_id=cve • CWE-352: Cross-Site Request Forgery (CSRF) •
CVE-2023-47242 – WordPress ANAC XML Bandi di Gara Plugin <= 7.5 is vulnerable to Cross Site Scripting (XSS)
https://notcve.org/view.php?id=CVE-2023-47242
07 Nov 2023 — Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Marco Milesi ANAC XML Bandi di Gara plugin <= 7.5 versions. Vulnerabilidad de Cross-Site Scripting (XSS) autenticada (con permisos de colaboradores o superiores) almacenada en el complemento Marco Milesi ANAC XML Bandi di Gara en versiones <=7.5. The ANAC XML Bandi di Gara plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in all versions up to, and including, 7.5 due to insufficient input... • https://patchstack.com/database/vulnerability/avcp/wordpress-anac-xml-bandi-di-gara-plugin-7-5-cross-site-scripting-xss-vulnerability?_s_id=cve • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •
CVE-2023-47245 – WordPress ANAC XML Viewer Plugin <= 1.7 is vulnerable to Cross Site Scripting (XSS)
https://notcve.org/view.php?id=CVE-2023-47245
07 Nov 2023 — Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Marco Milesi ANAC XML Viewer plugin <= 1.7 versions. Vulnerabilidad de Cross-Site Scripting (XSS) autenticada (con permisos de admin o superiores) almacenada en el complemento Marco Milesi ANAC XML Viewer en versiones <=1.7. The ANAC XML Viewer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 1.7 due to insufficient input sanitization and output escaping. This makes ... • https://patchstack.com/database/vulnerability/anac-xml-viewer/wordpress-anac-xml-viewer-plugin-1-7-cross-site-scripting-xss-vulnerability?_s_id=cve • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •
CVE-2023-47656 – WordPress ANAC XML Bandi di Gara Plugin <= 7.5 is vulnerable to Cross Site Scripting (XSS)
https://notcve.org/view.php?id=CVE-2023-47656
07 Nov 2023 — Auth. (editor+) Stored Cross-Site Scripting (XSS) vulnerability in Marco Milesi ANAC XML Bandi di Gara plugin <= 7.5 versions. Vulnerabilidad de Cross-Site Scripting (XSS) Almacenado autenticado (con permisos de editor o superiores) en el complemento Marco Milesi ANAC XML Bandi di Gara en versiones <= 7.5. The ANAC XML Bandi di Gara plugin for WordPress is vulnerable to Stored Cross-Site Scripting via an unknown parameter in versions up to, and including, 7.5 due to insufficient input sanitization and ou... • https://patchstack.com/database/vulnerability/avcp/wordpress-anac-xml-bandi-di-gara-plugin-7-5-cross-site-scripting-xss-vulnerability-2?_s_id=cve • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •
CVE-2023-45651 – WordPress WP Attachments Plugin <= 5.0.11 is vulnerable to Cross Site Request Forgery (CSRF)
https://notcve.org/view.php?id=CVE-2023-45651
12 Oct 2023 — Cross-Site Request Forgery (CSRF) vulnerability in Marco Milesi WP Attachments allows Cross Site Request Forgery.This issue affects WP Attachments: from n/a through 5.0.11. Vulnerabilidad de Cross-Site Request Forgery (CSRF) en el complemento Marco Milesi WP Attachments en versiones <= 5.0.6. The WP Attachments plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 5.0.11. This is due to missing or incorrect nonce validation on the wpatt_plugin_options func... • https://patchstack.com/database/vulnerability/wp-attachments/wordpress-wp-attachments-plugin-5-0-6-cross-site-request-forgery-csrf-vulnerability?_s_id=cve • CWE-352: Cross-Site Request Forgery (CSRF) •
CVE-2022-4330 – WP Attachments < 5.0.6 - Admin+ Stored XSS
https://notcve.org/view.php?id=CVE-2022-4330
21 Dec 2022 — The WP Attachments WordPress plugin before 5.0.6 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup). Las versiones del complemento WP Attachments de WordPress anteriores a la 5.0.6 no sanitizan ni escapan algunas de sus configuraciones, lo que podría permitir a usuarios con privilegios elevados, como el administrador, real... • https://wpscan.com/vulnerability/d3c39e17-1dc3-4275-97d8-543ca7226772 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •
CVE-2022-3469 – WP Attachments < 5.0.5 - Admin+ Stored Cross-Site Scripting
https://notcve.org/view.php?id=CVE-2022-3469
18 Oct 2022 — The WP Attachments WordPress plugin before 5.0.5 does not sanitize and escapes some of its settings, which could allow high-privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example, in multisite setup). El complemento de WordPress WP Attachments anterior a 5.0.5 no sanitiza y escapa a algunas de sus configuraciones, lo que podría permitir a usuarios con altos privilegios, como el administrador, realizar ataques de Cross-... • https://wpscan.com/vulnerability/017ca231-e019-4694-afa2-ab7f8481ae63 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •