6 results (0.001 seconds)

CVSS: 7.2EPSS: 0%CPEs: 1EXPL: 0

17 Oct 2023 — Unauth. Stored Cross-Site Scripting (XSS) vulnerability in UserFeedback Team User Feedback plugin <= 1.0.9 versions. Vulnerabilidad de Cross-Site Scripting (XSS)Almacenada No Autenticada en el complemento UserFeedback Team User Feedback en versiones <= 1.0.9. The User Feedback – Create Interactive Feedback Form, User Surveys, and Polls in Seconds plugin for WordPress is vulnerable to Cross-Site Scripting via an unknown parameter in all versions up to, and including, 1.0.9 due to insufficient input saniti... • https://patchstack.com/database/vulnerability/userfeedback-lite/wordpress-user-feedback-plugin-1-0-9-cross-site-scripting-xss-vulnerability?_s_id=cve • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVSS: 6.5EPSS: 0%CPEs: 1EXPL: 0

21 Jun 2023 — Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in MonsterInsights Pro allows Stored XSS.This issue affects MonsterInsights Pro: from n/a through 8.14.1. La vulnerabilidad de neutralización inadecuada de la entrada durante la generación de páginas web ('Scripting entre sitios') en MonsterInsights Pro permite almacenar XSS. Este problema afecta a MonsterInsights Pro: desde n/a hasta 8.14.1. The MonsterInsights Pro plugin for WordPress is vulnerable to Stored... • https://patchstack.com/database/vulnerability/google-analytics-premium/wordpress-monsterinsights-pro-plugin-8-14-1-cross-site-scripting-xss-vulnerability?_s_id=cve • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVSS: 6.5EPSS: 0%CPEs: 1EXPL: 0

10 May 2023 — Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in MonsterInsights plugin <= 8.14.0 versions. The Google Analytics by Monster Insights plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 8.14.0 due to insufficient input sanitization and output escaping on the style attribute. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a use... • https://patchstack.com/database/vulnerability/google-analytics-for-wordpress/wordpress-google-analytics-by-monsterinsights-plugin-8-14-0-cross-site-scripting-xss-vulnerability?_s_id=cve • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVSS: 6.5EPSS: 0%CPEs: 1EXPL: 0

09 May 2023 — Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in ExactMetrics plugin <= 7.14.1 versions. The ExactMetrics plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 7.14.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. Auth. • https://patchstack.com/database/vulnerability/google-analytics-dashboard-for-wp/wordpress-exactmetrics-plugin-7-14-1-cross-site-scripting-xss-vulnerability?_s_id=cve • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVSS: 6.4EPSS: 0%CPEs: 1EXPL: 1

13 Jan 2023 — The MonsterInsights WordPress plugin before 8.12.1 does not validate and escape some of its block options before outputting them back in a page/post where the block is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks. The MonsterInsights plugin for WordPress is vulnerable to Stored Cross-Site Scripting via unspecified block options (used in pages and posts) in versions up to, and including, 8.12.0 due to insufficient input sanitization and out... • https://wpscan.com/vulnerability/76d2963c-ebff-498f-9484-3c3008750c14 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVSS: 6.4EPSS: 24%CPEs: 1EXPL: 2

23 Dec 2022 — The MonsterInsights WordPress plugin before 8.9.1 does not sanitize or escape page titles in the top posts/pages section, allowing an unauthenticated attacker to inject arbitrary web scripts into the titles by spoofing requests to google analytics. El complemento MonsterInsights de WordPress anterior a 8.9.1 no sanitiza ni escapa los títulos de las páginas en la sección de publicaciones/páginas principales, lo que permite a un atacante no autenticado inyectar scripts en los títulos falsificando solicitudes ... • https://github.com/RandomRobbieBF/CVE-2022-3904 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •