Vulnerabilities > Dcurasi

DATE CVE VULNERABILITY TITLE RISK
2025-02-20 CVE-2024-13849 Cross-site Scripting vulnerability in Dcurasi Cookie Notice BAR
The Cookie Notice Bar plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 1.3.0 due to insufficient input sanitization and output escaping.
network
low complexity
dcurasi CWE-79
4.8
2024-07-21 CVE-2024-37522 Unspecified vulnerability in Dcurasi CC & BCC for Woocommerce Order Emails
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Dario Curasì CC & BCC for Woocommerce Order Emails allows Stored XSS.This issue affects CC & BCC for Woocommerce Order Emails: from n/a through 1.4.1.
network
low complexity
dcurasi
4.8