Vulnerabilities > Plugin

DATE CVE VULNERABILITY TITLE RISK
2023-04-05 CVE-2023-1871 Unspecified vulnerability in Plugin Yourchannel 1.2.3
The YourChannel plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.2.3.
network
low complexity
plugin
4.3
2023-03-22 CVE-2023-28659 SQL Injection vulnerability in Plugin Waiting
The Waiting: One-click Countdowns WordPress Plugin, version <= 0.6.2, is affected by an authenticated SQL injection vulnerability in the pbc_down[meta][id] parameter of the pbc_save_downs action.
network
low complexity
plugin CWE-89
8.8
2023-02-06 CVE-2022-4833 Unspecified vulnerability in Plugin Yourchannel 1.2.3
The YourChannel: Everything you want in a YouTube plugin WordPress plugin before 1.2.3 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as admins.
network
low complexity
plugin
5.4
2023-02-06 CVE-2023-0282 Unspecified vulnerability in Plugin Yourchannel
The YourChannel WordPress plugin before 1.2.2 does not sanitize and escape some parameters, which could allow users with a role as low as Subscriber to perform Cross-Site Scripting attacks.
network
low complexity
plugin
5.4