Vulnerabilities > Essentialplugin
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2024-06-06 | CVE-2024-4194 | Unspecified vulnerability in Essentialplugin Album and Image Gallery Plus Lightbox The The Album and Image Gallery plus Lightbox plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 2.0. | 7.3 |
2023-09-03 | CVE-2023-38516 | Unspecified vulnerability in Essentialplugin Audio Player With Playlist Ultimate Auth. | 5.4 |
2023-05-04 | CVE-2022-45818 | Unspecified vulnerability in Essentialplugin Hero Banner Ultimate Auth. | 5.4 |
2023-03-29 | CVE-2022-38077 | Cross-Site Request Forgery (CSRF) vulnerability in Essentialplugin Popup Anything Cross-Site Request Forgery (CSRF) vulnerability in WP OnlineSupport, Essential Plugin Popup Anything – A Marketing Popup and Lead Generation Conversions plugin <= 2.2.1 versions. | 8.8 |
2023-02-21 | CVE-2022-4791 | Unspecified vulnerability in Essentialplugin Product Slider and Carousel With Category With Woocommerce The Product Slider and Carousel with Category for WooCommerce WordPress plugin before 2.8 does not validate and escape one of its shortcode attributes, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attack. | 5.4 |
2023-02-06 | CVE-2022-4747 | Unspecified vulnerability in Essentialplugin Download Post Category Image With Grid and Slider The Post Category Image With Grid and Slider WordPress plugin before 1.4.8 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as admins. | 5.4 |
2023-02-06 | CVE-2022-4824 | Cross-site Scripting vulnerability in Essentialplugin WP Blog and Widget The WP Blog and Widgets WordPress plugin before 2.3.1 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as admins. | 5.4 |
2022-07-25 | CVE-2022-2115 | Unspecified vulnerability in Essentialplugin Popup Anything The Popup Anything WordPress plugin before 2.1.7 does not sanitise and escape a parameter before outputting it back in a frontend page, leading to a Reflected Cross-Site Scripting | 6.1 |
2021-11-29 | CVE-2021-24883 | Unspecified vulnerability in Essentialplugin Popup Anything The Popup Anything WordPress plugin before 2.0.4 does not escape the Link Text and Button Text fields of Popup, which could allow users with a role as low as Contributor to perform Cross-Site Scripting attacks | 5.4 |