Vulnerabilities > Plugin
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2023-04-05 | CVE-2023-1871 | Unspecified vulnerability in Plugin Yourchannel 1.2.3 The YourChannel plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.2.3. | 4.3 |
2023-03-22 | CVE-2023-28659 | SQL Injection vulnerability in Plugin Waiting The Waiting: One-click Countdowns WordPress Plugin, version <= 0.6.2, is affected by an authenticated SQL injection vulnerability in the pbc_down[meta][id] parameter of the pbc_save_downs action. | 8.8 |
2023-02-06 | CVE-2022-4833 | Unspecified vulnerability in Plugin Yourchannel 1.2.3 The YourChannel: Everything you want in a YouTube plugin WordPress plugin before 1.2.3 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as admins. | 5.4 |
2023-02-06 | CVE-2023-0282 | Unspecified vulnerability in Plugin Yourchannel The YourChannel WordPress plugin before 1.2.2 does not sanitize and escape some parameters, which could allow users with a role as low as Subscriber to perform Cross-Site Scripting attacks. | 5.4 |