Vulnerabilities > Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

DATE CVE VULNERABILITY TITLE RISK
2024-02-05 CVE-2024-0691 Cross-site Scripting vulnerability in Ninjateam Filebird
The FileBird plugin for WordPress is vulnerable to Stored Cross-Site Scripting via imported folder titles in all versions up to, and including, 5.5.8.1 due to insufficient input sanitization and output escaping.
network
low complexity
ninjateam CWE-79
4.8
2024-02-05 CVE-2024-0823 Cross-site Scripting vulnerability in Devscred Exclusive Addons for Elementor
The Exclusive Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Link To' url in carousels in all versions up to, and including, 2.6.8 due to insufficient input sanitization and output escaping on user supplied attributes.
network
low complexity
devscred CWE-79
5.4
2024-02-05 CVE-2024-0834 Cross-site Scripting vulnerability in Webtechstreet Elementor Addon Elements
The Elementor Addon Elements plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the link_to parameter in all versions up to, and including, 1.12.11 due to insufficient input sanitization and output escaping.
network
low complexity
webtechstreet CWE-79
5.4
2024-02-05 CVE-2024-0954 Cross-site Scripting vulnerability in Wpdeveloper Essential Addons for Elementor
The Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders plugin for WordPress is vulnerable to Stored Cross-Site Scripting through editing context via the 'data-eael-wrapper-link' wrapper in all versions up to, and including, 5.9.7 due to insufficient input sanitization and output escaping on user supplied protocols.
network
low complexity
wpdeveloper CWE-79
5.4
2024-02-05 CVE-2024-0961 Cross-site Scripting vulnerability in Siteorigin Widgets Bundle
The SiteOrigin Widgets Bundle plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the code editor in all versions up to, and including, 1.58.1 due to insufficient input sanitization and output escaping.
network
low complexity
siteorigin CWE-79
5.4
2024-02-05 CVE-2024-1046 Cross-site Scripting vulnerability in Properfraction Profilepress
The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin 'reg-number-field' shortcode in all versions up to, and including, 4.14.3 due to insufficient input sanitization and output escaping on user supplied attributes.
network
low complexity
properfraction CWE-79
5.4
2024-02-05 CVE-2023-6526 Cross-site Scripting vulnerability in Metabox Meta BOX
The Meta Box – WordPress Custom Fields Framework plugin for WordPress is vulnerable to Stored Cross-Site Scripting via custom post meta values displayed through the plugin's shortcode in all versions up to, and including, 5.9.2 due to insufficient input sanitization and output escaping.
network
low complexity
metabox CWE-79
5.4
2024-02-05 CVE-2023-6701 Cross-site Scripting vulnerability in Advancedcustomfields Advanced Custom Fields
The Advanced Custom Fields (ACF) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via a custom text field in all versions up to, and including, 6.2.4 due to insufficient input sanitization and output escaping.
network
low complexity
advancedcustomfields CWE-79
5.4
2024-02-05 CVE-2023-6807 Cross-site Scripting vulnerability in Generatepress
The GeneratePress Premium plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's custom meta output in all versions up to, and including, 2.3.2 due to insufficient input sanitization and output escaping on user supplied attributes.
network
low complexity
generatepress CWE-79
5.4
2024-02-05 CVE-2023-6808 Cross-site Scripting vulnerability in Tms-Outsource Amelia
The Booking for Appointments and Events Calendar – Amelia plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in all versions up to, and including, 1.0.93 due to insufficient input sanitization and output escaping on user supplied attributes.
network
low complexity
tms-outsource CWE-79
5.4