Vulnerabilities > Plugin Planet > Medium

DATE CVE VULNERABILITY TITLE RISK
2023-12-14 CVE-2023-49743 Unspecified vulnerability in Plugin-Planet Dashboard Widget Suite
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Jeff Starr Dashboard Widgets Suite allows Stored XSS.This issue affects Dashboard Widgets Suite: from n/a through 3.4.1.
network
low complexity
plugin-planet
4.8
2023-10-20 CVE-2023-5614 Cross-site Scripting vulnerability in Plugin-Planet Theme Switcha
The Theme Switcha plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'theme_switcha_list' shortcode in all versions up to, and including, 3.3 due to insufficient input sanitization and output escaping on user supplied attributes.
network
low complexity
plugin-planet CWE-79
5.4
2023-09-09 CVE-2023-4838 Unspecified vulnerability in Plugin-Planet Simple Download Counter
The Simple Download Counter plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcodes in versions up to, and including, 1.6 due to insufficient input sanitization and output escaping on user supplied attributes like 'before' and 'after'.
network
low complexity
plugin-planet
5.4
2023-09-06 CVE-2023-4779 Unspecified vulnerability in Plugin-Planet User Submitted Posts
The User Submitted Posts plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's [usp_gallery] shortcode in versions up to, and including, 20230811 due to insufficient input sanitization and output escaping on user supplied attributes like 'before'.
network
low complexity
plugin-planet
5.4
2023-08-15 CVE-2023-4308 Unspecified vulnerability in Plugin-Planet User Submitted Posts
The User Submitted Posts plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘user-submitted-content’ parameter in versions up to, and including, 20230809 due to insufficient input sanitization and output escaping.
network
low complexity
plugin-planet
5.4
2023-05-06 CVE-2023-26517 Unspecified vulnerability in Plugin-Planet Dashboard Widget Suite
Auth.
network
low complexity
plugin-planet
4.8
2022-04-15 CVE-2022-27850 Unspecified vulnerability in Plugin-Planet Simple Ajax Chat
Cross-Site Request Forgery (CSRF) in Simple Ajax Chat (WordPress plugin) <= 20220115 allows an attacker to clear the chat log or delete a chat message.
network
low complexity
plugin-planet
4.3
2022-03-25 CVE-2022-25610 Cross-site Scripting vulnerability in Plugin-Planet Simple Ajax Chat
Unauthenticated Stored Cross-Site Scripting (XSS) in Simple Ajax Chat <= 20220115 allows an attacker to store the malicious code.
network
low complexity
plugin-planet CWE-79
6.1
2022-03-11 CVE-2022-25601 Cross-site Scripting vulnerability in multiple products
Reflected Cross-Site Scripting (XSS) vulnerability affecting parameter &tab discovered in Contact Form X WordPress plugin (versions <= 2.4).
network
low complexity
plugin-planet fedoraproject CWE-79
6.1
2021-07-12 CVE-2021-24408 Unspecified vulnerability in Plugin-Planet Prismatic
The Prismatic WordPress plugin before 2.8 does not sanitise or validate some of its shortcode parameters, allowing users with a role as low as Contributor to set Cross-Site payload in them.
network
low complexity
plugin-planet
5.4