Vulnerabilities > Bplugins > Icons Font Loader

DATE CVE VULNERABILITY TITLE RISK
2023-11-06 CVE-2023-46084 SQL Injection vulnerability in Bplugins Icons Font Loader 1.0/1.1.2
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in bPlugins LLC Icons Font Loader allows SQL Injection.This issue affects Icons Font Loader: from n/a through 1.1.2.
network
low complexity
bplugins CWE-89
8.8
2023-11-02 CVE-2023-5860 Unrestricted Upload of File with Dangerous Type vulnerability in Bplugins Icons Font Loader 1.0/1.1.2
The Icons Font Loader plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the upload function in all versions up to, and including, 1.1.2.
network
low complexity
bplugins CWE-434
7.2