Vulnerabilities > Fullworksplugins

DATE CVE VULNERABILITY TITLE RISK
2023-05-02 CVE-2023-1554 Unspecified vulnerability in Fullworksplugins Quick Paypal Payments
The Quick Paypal Payments WordPress plugin before 5.7.26.4 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)
network
low complexity
fullworksplugins
4.8
2023-04-25 CVE-2023-23889 Unspecified vulnerability in Fullworksplugins Quick Paypal Payments
Auth.
network
low complexity
fullworksplugins
5.4
2023-04-25 CVE-2022-47608 Cross-site Scripting vulnerability in Fullworksplugins Quick Contact Form
Auth.
network
low complexity
fullworksplugins CWE-79
4.8
2023-04-07 CVE-2023-25702 Unspecified vulnerability in Fullworksplugins Quick Paypal Payments
Auth.
network
low complexity
fullworksplugins
4.8
2023-04-07 CVE-2023-25713 Unspecified vulnerability in Fullworksplugins Quick Paypal Payments
Unauth.
network
low complexity
fullworksplugins
6.1
2023-04-07 CVE-2023-23885 Unspecified vulnerability in Fullworksplugins Quick Contact Form
Auth.
network
low complexity
fullworksplugins
5.4
2023-04-06 CVE-2023-23979 Unspecified vulnerability in Fullworksplugins Quick Event Manager
Unauth.
network
low complexity
fullworksplugins
6.1
2023-03-28 CVE-2022-46863 Unspecified vulnerability in Fullworksplugins Quick Event Manager
Auth.
network
low complexity
fullworksplugins
4.8
2023-03-01 CVE-2023-23974 Cross-Site Request Forgery (CSRF) vulnerability in Fullworksplugins Quick Event Manager
Cross-Site Request Forgery (CSRF) vulnerability in Fullworks Quick Event Manager plugin <= 9.7.4 affecting all registration actions (delete, delete all, edit, update).
network
low complexity
fullworksplugins CWE-352
5.4
2023-01-20 CVE-2023-23491 Cross-site Scripting vulnerability in Fullworksplugins Quick Event Manager
The Quick Event Manager WordPress Plugin, version < 9.7.5, is affected by a reflected cross-site scripting vulnerability in the 'category' parameter of its 'qem_ajax_calendar' action.
network
low complexity
fullworksplugins CWE-79
6.1