Vulnerabilities > Pluginus

DATE CVE VULNERABILITY TITLE RISK
2023-10-20 CVE-2023-4943 Missing Authorization vulnerability in Pluginus Bear - Woocommerce Bulk Editor and products Manager Professional
The BEAR for WordPress is vulnerable to Missing Authorization in versions up to, and including, 1.1.3.3.
network
low complexity
pluginus CWE-862
4.3
2023-10-18 CVE-2023-4938 Missing Authorization vulnerability in Pluginus Bear - Woocommerce Bulk Editor and products Manager Professional
The BEAR for WordPress is vulnerable to Missing Authorization in versions up to, and including, 1.1.3.3.
network
low complexity
pluginus CWE-862
4.3
2023-10-17 CVE-2023-44990 Cross-site Scripting vulnerability in Pluginus Wolf - Wordpress Posts Bulk Editor and products Manager Professional
Auth.
network
low complexity
pluginus CWE-79
4.8
2023-08-18 CVE-2023-31218 Cross-site Scripting vulnerability in Pluginus Wolf - Wordpress Posts Bulk Editor and products Manager Professional
Cross-Site Request Forgery (CSRF) leading to Stored Cross-Site Scripting (XSS) vulnerability in realmag777 WOLF – WordPress Posts Bulk Editor and Manager Professional plugin <= 1.0.6 versions.
network
low complexity
pluginus CWE-79
6.1
2023-06-22 CVE-2023-34028 Cross-Site Request Forgery (CSRF) vulnerability in Pluginus Wolf - Wordpress Posts Bulk Editor and Manager Professional
Cross-Site Request Forgery (CSRF) vulnerability in realmag777 WOLF – WordPress Posts Bulk Editor and Manager Professional plugin <= 1.0.7 versions.
network
low complexity
pluginus CWE-352
8.8
2023-06-09 CVE-2023-2555 Unspecified vulnerability in Pluginus Wordpress Currency Switcher Professional
The WPCS – WordPress Currency Switcher Professional plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the create function in versions up to, and including, 1.1.9.
network
low complexity
pluginus
4.3
2023-06-09 CVE-2023-2556 Unspecified vulnerability in Pluginus Wordpress Currency Switcher
The WPCS – WordPress Currency Switcher Professional plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the anonymous function for the wpcs_sd_delete action in versions up to, and including, 1.1.9.
network
low complexity
pluginus
4.3
2023-06-09 CVE-2023-2557 Missing Authorization vulnerability in Pluginus Wordpress Currency Switcher Professional
The WPCS – WordPress Currency Switcher Professional plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the save function in versions up to, and including, 1.1.9.
network
low complexity
pluginus CWE-862
4.3
2023-06-09 CVE-2023-2558 Unspecified vulnerability in Pluginus Wordpress Currency Switcher Professional
The WPCS – WordPress Currency Switcher Professional plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's wpcs_current_currency shortcode in versions up to, and including, 1.1.9 due to insufficient input sanitization and output escaping on user supplied attributes.
network
low complexity
pluginus
5.4
2023-05-28 CVE-2023-33314 Cross-Site Request Forgery (CSRF) vulnerability in Pluginus Bear - Woocommerce Bulk Editor and products Manager Professional
Cross-Site Request Forgery (CSRF) vulnerability in realmag777 BEAR plugin <= 1.1.3.1 versions.
network
low complexity
pluginus CWE-352
8.8