Vulnerabilities > Codesupply
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2024-09-27 | CVE-2024-8965 | Cross-site Scripting vulnerability in Codesupply Absolute Reviews The Absolute Reviews plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Name' field of a custom post criteria in all versions up to, and including, 1.1.3 due to insufficient input sanitization and output escaping. | 5.4 |
2024-09-26 | CVE-2024-9025 | Missing Authorization vulnerability in Codesupply Sight The Sight – Professional Image Gallery and Portfolio plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'handler_post_title' function in all versions up to, and including, 1.1.2. | 5.3 |
2023-07-12 | CVE-2021-4426 | Unspecified vulnerability in Codesupply Absolute Reviews The Absolute Reviews plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.0.8. | 4.3 |
2021-11-08 | CVE-2021-24840 | Authorization Bypass Through User-Controlled Key vulnerability in Codesupply Squaretype The Squaretype WordPress theme before 3.0.4 allows unauthenticated users to manipulate the query_vars used to retrieve the posts to display in one of its REST endpoint, without any validation. | 5.3 |