Vulnerabilities > Designchemical

DATE CVE VULNERABILITY TITLE RISK
2023-09-12 CVE-2023-4890 Unspecified vulnerability in Designchemical Jquery Accordion Menu Widget 3.1.2
The JQuery Accordion Menu Widget for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'dcwp-jquery-accordion' shortcode in versions up to, and including, 3.1.2 due to insufficient input sanitization and output escaping on user supplied attributes.
network
low complexity
designchemical
5.4
2019-03-21 CVE-2018-20555 Information Exposure vulnerability in Designchemical Social Network Tabs 1.7.1
The Design Chemical Social Network Tabs plugin 1.7.1 for WordPress allows remote attackers to discover Twitter access_token, access_token_secret, consumer_key, and consumer_secret values by reading the dcwp_twitter.php source code.
network
low complexity
designchemical CWE-200
critical
9.8