Vulnerabilities > Awplife

DATE CVE VULNERABILITY TITLE RISK
2024-06-21 CVE-2024-5059 Unspecified vulnerability in Awplife Event Monster
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in A WP Life Event Management Tickets Booking.This issue affects Event Management Tickets Booking: from n/a through 1.4.0.
network
low complexity
awplife
7.5
2024-06-10 CVE-2024-35717 Unspecified vulnerability in Awplife Media Slider
Missing Authorization vulnerability in A WP Life Media Slider – Photo Sleder, Video Slider, Link Slider, Carousal Slideshow.This issue affects Media Slider – Photo Sleder, Video Slider, Link Slider, Carousal Slideshow: from n/a through 1.3.9.
network
low complexity
awplife
8.8
2024-06-10 CVE-2024-35720 Unspecified vulnerability in Awplife Album Gallery
Missing Authorization vulnerability in A WP Life Album Gallery – WordPress Gallery.This issue affects Album Gallery – WordPress Gallery: from n/a through 1.5.7.
network
low complexity
awplife
8.8
2024-06-10 CVE-2024-35721 Unspecified vulnerability in Awplife Image Gallery
Missing Authorization vulnerability in A WP Life Image Gallery – Lightbox Gallery, Responsive Photo Gallery, Masonry Gallery.This issue affects Image Gallery – Lightbox Gallery, Responsive Photo Gallery, Masonry Gallery: from n/a through 1.4.5.
network
low complexity
awplife
8.8
2024-06-10 CVE-2024-35722 Unspecified vulnerability in Awplife Slider Responsive Slideshow
Missing Authorization vulnerability in A WP Life Slider Responsive Slideshow – Image slider, Gallery slideshow.This issue affects Slider Responsive Slideshow – Image slider, Gallery slideshow: from n/a through 1.4.0.
network
low complexity
awplife
8.8
2023-12-21 CVE-2023-47525 Unspecified vulnerability in Awplife Event Monster
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in A WP Life Event Monster – Event Management, Tickets Booking, Upcoming Event allows Stored XSS.This issue affects Event Monster – Event Management, Tickets Booking, Upcoming Event: from n/a through 1.3.2.
network
low complexity
awplife
5.4
2023-10-04 CVE-2023-5291 Unspecified vulnerability in Awplife Blog Filter
The Blog Filter plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'AWL-BlogFilter' shortcode in versions up to, and including, 1.5.3 due to insufficient input sanitization and output escaping on user supplied attributes.
network
low complexity
awplife
5.4
2023-09-30 CVE-2023-5295 Unspecified vulnerability in Awplife Blog Filter
The Blog Filter plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'vivafbcomment' shortcode in versions up to, and including, 1.4 due to insufficient input sanitization and output escaping on user supplied attributes.
network
low complexity
awplife
5.4
2023-07-17 CVE-2023-23646 Unspecified vulnerability in Awplife Album Gallery
Cross-Site Request Forgery (CSRF) vulnerability in A WP Life Album Gallery – WordPress Gallery plugin <= 1.4.9 versions.
network
low complexity
awplife
8.8
2022-11-21 CVE-2022-3336 Unspecified vulnerability in Awplife Event Monster
The Event Monster WordPress plugin before 1.2.0 does not have CSRF check when deleting visitors, which could allow attackers to make logged in admin delete arbitrary visitors via a CSRF attack
network
low complexity
awplife
4.3