Vulnerabilities > Connekthq

DATE CVE VULNERABILITY TITLE RISK
2021-06-01 CVE-2021-24334 Unspecified vulnerability in Connekthq Instant Images - ONE Click Unsplash Uploads
The Instant Images – One Click Unsplash Uploads WordPress plugin before 4.4.0.1 did not properly validate and sanitise its unsplash_download_w and unsplash_download_h parameter settings (/wp-admin/upload.php?page=instant-images), only validating them client side before saving them, leading to a Stored Cross-Site Scripting issue.
network
low complexity
connekthq
5.4
2021-03-18 CVE-2021-24140 SQL Injection vulnerability in Connekthq Ajax Load More
Unvalidated input in the Ajax Load More WordPress plugin, versions before 5.3.2, lead to SQL Injection in POST /wp-admin/admin-ajax.php with param repeater=' or sleep(5)#&type=test.
network
low complexity
connekthq CWE-89
7.2