Vulnerabilities > Quadlayers

DATE CVE VULNERABILITY TITLE RISK
2022-08-22 CVE-2022-2361 Cross-site Scripting vulnerability in Quadlayers WP Social Chat
The WP Social Chat WordPress plugin before 6.0.5 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks.
network
low complexity
quadlayers CWE-79
4.8
2022-02-18 CVE-2022-23981 Unspecified vulnerability in Quadlayers Perfect Brands for Woocommerce
The vulnerability allows Subscriber+ level users to create brands in WordPress Perfect Brands for WooCommerce plugin (versions <= 2.0.4).
network
low complexity
quadlayers
4.3
2022-02-18 CVE-2022-23982 Information Exposure vulnerability in Quadlayers Perfect Brands for Woocommerce
The vulnerability discovered in WordPress Perfect Brands for WooCommerce plugin (versions <= 2.0.4) allows server information exposure.
network
low complexity
quadlayers CWE-200
7.5
2019-08-29 CVE-2019-15779 Cross-Site Request Forgery (CSRF) vulnerability in Quadlayers WP Social Feed Gallery
The insta-gallery plugin before 2.4.8 for WordPress has no nonce validation for qligg_dismiss_notice or qligg_form_item_delete.
network
low complexity
quadlayers CWE-352
8.8