Vulnerabilities > Flippercode > Medium

DATE CVE VULNERABILITY TITLE RISK
2023-07-01 CVE-2021-4386 Unspecified vulnerability in Flippercode Wp-Security-Questions
The WP Security Question plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.0.5.
network
low complexity
flippercode
4.3
2023-04-04 CVE-2023-23878 Unspecified vulnerability in Flippercode WP Google MAP
Auth.
network
low complexity
flippercode
5.4
2021-08-09 CVE-2021-24502 Unspecified vulnerability in Flippercode WP Google MAP 1.1.0/1.2.0
The WP Google Map WordPress plugin before 1.7.7 did not sanitise or escape the Map Title before outputting them in the page, leading to a Stored Cross-Site Scripting issue by high privilege users, even when the unfiltered_html capability is disallowed
network
low complexity
flippercode
4.8
2019-08-12 CVE-2016-10878 Cross-site Scripting vulnerability in Flippercode WP Google MAP
The wp-google-map-plugin plugin before 3.1.2 for WordPress has XSS.
network
low complexity
flippercode CWE-79
6.1
2019-08-12 CVE-2015-9305 Cross-site Scripting vulnerability in Flippercode WP Google MAP
The wp-google-map-plugin plugin before 2.3.7 for WordPress has XSS related to the add_query_arg() and remove_query_arg() functions.
network
low complexity
flippercode CWE-79
6.1
2018-05-14 CVE-2018-0577 Cross-site Scripting vulnerability in Flippercode WP Google MAP
Cross-site scripting vulnerability in WP Google Map Plugin prior to version 4.0.4 for WordPress allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
network
low complexity
flippercode CWE-79
5.4