Vulnerabilities > AYS PRO

DATE CVE VULNERABILITY TITLE RISK
2024-11-14 CVE-2024-10571 Unspecified vulnerability in Ays-Pro Chartify
The Chartify – WordPress Chart Plugin plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 2.9.5 via the 'source' parameter.
network
low complexity
ays-pro
critical
9.8
2024-09-27 CVE-2024-7713 Cleartext Transmission of Sensitive Information vulnerability in Ays-Pro Chatgpt Assistant
The AI ChatBot with ChatGPT and Content Generator by AYS WordPress plugin before 2.1.0 discloses the Open AI API Key, allowing unauthenticated users to obtain it
network
low complexity
ays-pro CWE-319
7.5
2024-09-27 CVE-2024-7714 Unspecified vulnerability in Ays-Pro Chatgpt Assistant
The AI ChatBot with ChatGPT and Content Generator by AYS WordPress plugin before 2.1.0 lacks sufficient access controls allowing an unauthenticated user to disconnect the AI ChatBot with ChatGPT and Content Generator by AYS WordPress plugin before 2.1.0 from OpenAI, thereby disabling the AI ChatBot with ChatGPT and Content Generator by AYS WordPress plugin before 2.1.0.
network
low complexity
ays-pro
7.5
2024-09-04 CVE-2024-6888 Cross-site Scripting vulnerability in Ays-Pro Secure Copy Content Protection and Content Locking
The Secure Copy Content Protection and Content Locking WordPress plugin before 4.1.7 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)
network
low complexity
ays-pro CWE-79
4.8
2024-09-04 CVE-2024-6889 Cross-site Scripting vulnerability in Ays-Pro Secure Copy Content Protection and Content Locking
The Secure Copy Content Protection and Content Locking WordPress plugin before 4.1.7 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).
network
low complexity
ays-pro CWE-79
4.8
2024-07-11 CVE-2024-6138 Cross-site Scripting vulnerability in Ays-Pro Secure Copy Content Protection and Content Locking
The Secure Copy Content Protection and Content Locking WordPress plugin before 4.0.9 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).
network
low complexity
ays-pro CWE-79
4.8
2024-07-09 CVE-2024-37442 Injection vulnerability in Ays-Pro Photo Gallery
Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') vulnerability in Photo Gallery Team Photo Gallery by Ays allows Code Injection.This issue affects Photo Gallery by Ays: from n/a before 5.7.1.
network
low complexity
ays-pro CWE-74
5.5
2024-02-12 CVE-2023-6591 Cross-site Scripting vulnerability in Ays-Pro Popup BOX 20.8.7/20.8.8/20.8.9
The Popup Box WordPress plugin before 20.9.0 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed
network
low complexity
ays-pro CWE-79
4.8
2024-02-12 CVE-2023-47526 Cross-site Scripting vulnerability in Ays-Pro Chartify 2.0.6
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Chart Builder Team Chartify – WordPress Chart Plugin allows Stored XSS.This issue affects Chartify – WordPress Chart Plugin: from n/a through 2.0.6.
network
low complexity
ays-pro CWE-79
4.8
2024-02-07 CVE-2024-1078 Missing Authorization vulnerability in Ays-Pro Quiz Maker
The Quiz Maker plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the ays_quick_start() and add_question_rows() functions in all versions up to, and including, 6.5.2.4.
network
low complexity
ays-pro CWE-862
4.3