Vulnerabilities > Metagauss > Medium
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2023-10-31 | CVE-2023-4250 | Cross-site Scripting vulnerability in Metagauss Eventprime The EventPrime WordPress plugin before 3.2.0 does not sanitise and escape some parameters before outputting them back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin. | 6.1 |
2023-10-31 | CVE-2023-4251 | Cross-Site Request Forgery (CSRF) vulnerability in Metagauss Eventprime The EventPrime WordPress plugin before 3.2.0 does not have CSRF checks when creating bookings, which could allow attackers to make logged in users create unwanted bookings via CSRF attacks. | 4.3 |
2023-10-31 | CVE-2023-5238 | Cross-site Scripting vulnerability in Metagauss Eventprime The EventPrime WordPress plugin before 3.2.0 does not sanitise and escape a parameter before outputting it back in the page, leading to an HTML Injection on the plugin in the search area of the website. | 6.1 |
2023-10-31 | CVE-2023-5519 | Cross-Site Request Forgery (CSRF) vulnerability in Metagauss Eventprime The EventPrime WordPress plugin before 3.2.0 does not have CSRF checks when creating bookings, which could allow attackers to make logged in users create unwanted bookings via CSRF attacks. | 4.3 |
2023-10-25 | CVE-2023-45637 | Cross-site Scripting vulnerability in Metagauss Eventprime Unauth. | 6.1 |
2023-08-31 | CVE-2023-3404 | Unspecified vulnerability in Metagauss Profilegrid The ProfileGrid plugin for WordPress is vulnerable to unauthorized decryption of private information in versions up to, and including, 5.5.0. | 4.9 |
2023-07-18 | CVE-2023-3403 | Unspecified vulnerability in Metagauss Profilegrid The ProfileGrid plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'pm_upload_csv' function in versions up to, and including, 5.5.1. | 4.3 |
2023-06-20 | CVE-2023-35884 | Cross-site Scripting vulnerability in Metagauss Eventprime Unauth. | 6.1 |
2023-05-28 | CVE-2023-33326 | Cross-site Scripting vulnerability in Metagauss Eventprime Unauth. | 6.1 |
2023-04-17 | CVE-2023-0889 | Unspecified vulnerability in Metagauss Themeflection Numbers Themeflection Numbers WordPress plugin before 2.0.1 does not have authorisation and CSRF check in an AJAX action, and does not ensure that the options to be updated belong to the plugin. | 6.5 |