Vulnerabilities > AYS PRO > Medium

DATE CVE VULNERABILITY TITLE RISK
2024-09-04 CVE-2024-6888 Cross-site Scripting vulnerability in Ays-Pro Secure Copy Content Protection and Content Locking
The Secure Copy Content Protection and Content Locking WordPress plugin before 4.1.7 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)
network
low complexity
ays-pro CWE-79
4.8
2024-09-04 CVE-2024-6889 Cross-site Scripting vulnerability in Ays-Pro Secure Copy Content Protection and Content Locking
The Secure Copy Content Protection and Content Locking WordPress plugin before 4.1.7 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).
network
low complexity
ays-pro CWE-79
4.8
2024-07-11 CVE-2024-6138 Cross-site Scripting vulnerability in Ays-Pro Secure Copy Content Protection and Content Locking
The Secure Copy Content Protection and Content Locking WordPress plugin before 4.0.9 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).
network
low complexity
ays-pro CWE-79
4.8
2024-07-09 CVE-2024-37442 Injection vulnerability in Ays-Pro Photo Gallery
Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') vulnerability in Photo Gallery Team Photo Gallery by Ays allows Code Injection.This issue affects Photo Gallery by Ays: from n/a before 5.7.1.
network
low complexity
ays-pro CWE-74
5.5
2024-02-12 CVE-2023-6591 Cross-site Scripting vulnerability in Ays-Pro Popup BOX 20.8.7/20.8.8/20.8.9
The Popup Box WordPress plugin before 20.9.0 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed
network
low complexity
ays-pro CWE-79
4.8
2024-02-12 CVE-2023-47526 Cross-site Scripting vulnerability in Ays-Pro Chartify 2.0.6
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Chart Builder Team Chartify – WordPress Chart Plugin allows Stored XSS.This issue affects Chartify – WordPress Chart Plugin: from n/a through 2.0.6.
network
low complexity
ays-pro CWE-79
4.8
2024-02-07 CVE-2024-1078 Missing Authorization vulnerability in Ays-Pro Quiz Maker
The Quiz Maker plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the ays_quick_start() and add_question_rows() functions in all versions up to, and including, 6.5.2.4.
network
low complexity
ays-pro CWE-862
4.3
2024-02-07 CVE-2024-1079 Missing Authorization vulnerability in Ays-Pro Quiz Maker
The Quiz Maker plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the ays_show_results() function in all versions up to, and including, 6.5.2.4.
network
low complexity
ays-pro CWE-862
5.3
2024-01-12 CVE-2024-22027 Improper Input Validation vulnerability in Ays-Pro Quiz Maker
Improper input validation vulnerability in WordPress Quiz Maker Plugin prior to 6.5.0.6 allows a remote authenticated attacker to perform a Denial of Service (DoS) attack against external services.
network
low complexity
ays-pro CWE-20
6.5
2023-12-26 CVE-2023-6155 Improper Authentication vulnerability in Ays-Pro Quiz Maker
The Quiz Maker WordPress plugin before 6.4.9.5 does not adequately authorize the `ays_quiz_author_user_search` AJAX action, allowing an unauthenticated attacker to perform a search for users of the system, ultimately leaking user email addresses.
network
low complexity
ays-pro CWE-287
5.3