7 results (0.004 seconds)

CVSS: 5.9EPSS: 0%CPEs: 1EXPL: 0

20 Jul 2023 — Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Never5 Post Connector plugin <= 1.0.9 versions. Vulnerabilidad de Cross-Site Scripting (XSS) almacenado con necesidad de autenticación (permisos de administrador o superior) en el plugin Never5 Post Connector en versiones anteriores, e incluyendo la 1.0.9. The Post Connector plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versions up to, and including, 1.0.9 due to insufficient input sanitization and ou... • https://patchstack.com/database/vulnerability/post-connector/wordpress-post-connector-plugin-1-0-9-cross-site-scripting-xss-vulnerability?_s_id=cve • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVSS: 5.5EPSS: 5%CPEs: 1EXPL: 1

14 Oct 2022 — Cross-site Scripting (XSS) - Stored in GitHub repository barrykooij/related-posts-for-wp prior to 2.1.3. Una vulnerabilidad de tipo Cross-site Scripting (XSS) - Almacenado en el repositorio de GitHub barrykooij/related-posts-for-wp versiones anteriores a 2.1.3 The Related Posts for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘heading_text’ parameter in versions up to, and including, 2.1.2 due to insufficient input sanitization and output escaping. This makes it possib... • https://github.com/barrykooij/related-posts-for-wp/commit/37733398dd88863fc0bdb3d6d378598429fd0b81 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVSS: 5.5EPSS: 0%CPEs: 1EXPL: 1

17 May 2021 — The Related Posts for WordPress plugin through 2.0.4 does not sanitise its heading_text and CSS settings, allowing high privilege users (admin) to set XSS payloads in them, leading to Stored Cross-Site Scripting issues. El plugin Related Posts para WordPress versiones hasta 2.0.4, no sanea sus ajustes heading_text y CSS, permitiendo a usuarios con privilegios elevados (admin) establecer cargas útiles XSS en ellos, lo que conlleva a problemas de tipo Cross-Site Scripting Almacenado • https://m0ze.ru/vulnerability/%5B2021-04-18%5D-%5BWordPress%5D-%5BCWE-79%5D-Related-Posts-for-WordPress-WordPress-Plugin-v2.0.4.txt • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVSS: 5.4EPSS: 0%CPEs: 1EXPL: 1

15 Mar 2021 — Unvalidated input and lack of output encoding within the Related Posts for WordPress plugin before 2.0.4 lead to a Reflected Cross-Site Scripting (XSS) vulnerability within the 'lang' GET parameter while editing a post, triggered when users with the capability of editing posts access a malicious URL. Una entrada no comprobada y una falta de codificación de la salida dentro del plugin Related Posts para WordPress versiones anteriores a 2.0.4, conllevan a una vulnerabilidad de tipo Cross-Site Scripting (XSS) ... • https://wpscan.com/vulnerability/7593d5c8-cbc2-4469-b36b-5d4fb6d49718 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVSS: 6.1EPSS: 0%CPEs: 1EXPL: 0

20 Apr 2015 — The download-monitor plugin before 1.7.1 for WordPress has XSS related to add_query_arg. El complemento download-monitor versiones anteriores a 1.7.1 para WordPress tiene XSS relacionado con add_query_arg • https://wordpress.org/plugins/download-monitor/#developers • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVSS: 6.1EPSS: 0%CPEs: 1EXPL: 0

20 Apr 2015 — The Related Posts plugin before 1.8.2 for WordPress has XSS via add_query_arg() and remove_query_arg(). El plugin Related Posts versiones anteriores a 1.8.2 para WordPress, tiene una vulnerabilidad de tipo XSS por medio de las funciones add_query_arg() y remove_query_arg(). • https://blog.sucuri.net/2015/04/security-advisory-xss-vulnerability-affecting-multiple-wordpress-plugins.html • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVSS: 6.1EPSS: 0%CPEs: 1EXPL: 0

20 Apr 2015 — The Post Connector plugin before 1.0.4 for WordPress has XSS via add_query_arg() and remove_query_arg(). El plugin Post Connector versiones anteriores a 1.0.4 para WordPress, tiene una vulnerabilidad de tipo XSS por medio de las funciones add_query_arg() y remove_query_arg(). • https://www.barrykooij.com/several-security-updates-released • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •