Vulnerabilities > Mainwp
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2023-02-23 | CVE-2023-23659 | Cross-Site Request Forgery (CSRF) vulnerability in Mainwp Motomo Cross-Site Request Forgery (CSRF) vulnerability in MainWP Matomo Extension <= 4.0.4 versions. | 8.8 |
2021-11-23 | CVE-2021-24877 | Unspecified vulnerability in Mainwp Child The MainWP Child WordPress plugin before 4.1.8 does not validate the orderby and order parameter before using them in a SQL statement, leading to an SQL injection exploitable by high privilege users such as admin when the Backup and Staging by WP Time Capsule plugin is installed | 7.2 |
2021-10-18 | CVE-2021-24754 | SQL Injection vulnerability in Mainwp Child Reports The MainWP Child Reports WordPress plugin before 2.0.8 does not validate or sanitise the order parameter before using it in a SQL statement in the admin dashboard, leading to an SQL injection issue | 7.2 |