Vulnerabilities > Etoilewebdesign > Ultimate Reviews

DATE CVE VULNERABILITY TITLE RISK
2024-03-15 CVE-2024-25597 Unspecified vulnerability in Etoilewebdesign Ultimate Reviews
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Etoile Web Design Ultimate Reviews allows Stored XSS.This issue affects Ultimate Reviews: from n/a through 3.2.8.
network
low complexity
etoilewebdesign
6.1
2023-06-07 CVE-2020-36726 Deserialization of Untrusted Data vulnerability in Etoilewebdesign Ultimate Reviews
The Ultimate Reviews plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 2.1.32 via deserialization of untrusted input in several vulnerable functions.
network
low complexity
etoilewebdesign CWE-502
critical
9.8
2022-01-28 CVE-2022-23979 Cross-site Scripting vulnerability in Etoilewebdesign Ultimate Reviews
Authenticated (admin+) Stored Cross-Site Scripting (XSS) vulnerability discovered in Ultimate Reviews WordPress plugin (versions <= 3.0.15).
network
low complexity
etoilewebdesign CWE-79
4.8