Vulnerabilities > Plugin > Yourchannel > Medium
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2023-04-05 | CVE-2023-1865 | Unspecified vulnerability in Plugin Yourchannel 1.2.3 The YourChannel plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check when resetting plugin settings via the yrc_nuke GET parameter in versions up to, and including, 1.2.3. | 6.5 |
2023-04-05 | CVE-2023-1866 | Unspecified vulnerability in Plugin Yourchannel 1.2.3 The YourChannel plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.2.3. | 4.3 |
2023-04-05 | CVE-2023-1867 | Unspecified vulnerability in Plugin Yourchannel 1.2.3 The YourChannel plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.2.3. | 4.3 |
2023-04-05 | CVE-2023-1868 | Unspecified vulnerability in Plugin Yourchannel 1.2.3 The YourChannel plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check when clearing the plugin cache via the yrc_clear_cache GET parameter in versions up to, and including, 1.2.3. | 5.3 |
2023-04-05 | CVE-2023-1869 | Cross-site Scripting vulnerability in Plugin Yourchannel 1.2.3 The YourChannel plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versions up to, and including, 1.2.5 due to insufficient input sanitization and output escaping. | 4.8 |
2023-04-05 | CVE-2023-1870 | Unspecified vulnerability in Plugin Yourchannel 1.2.3 The YourChannel plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.2.3. | 4.3 |
2023-04-05 | CVE-2023-1871 | Unspecified vulnerability in Plugin Yourchannel 1.2.3 The YourChannel plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.2.3. | 4.3 |
2023-02-06 | CVE-2022-4833 | Unspecified vulnerability in Plugin Yourchannel 1.2.3 The YourChannel: Everything you want in a YouTube plugin WordPress plugin before 1.2.3 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as admins. | 5.4 |
2023-02-06 | CVE-2023-0282 | Unspecified vulnerability in Plugin Yourchannel The YourChannel WordPress plugin before 1.2.2 does not sanitize and escape some parameters, which could allow users with a role as low as Subscriber to perform Cross-Site Scripting attacks. | 5.4 |