Vulnerabilities > Rextheme
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2023-09-27 | CVE-2023-40663 | Cross-site Scripting vulnerability in Rextheme WP VR Unauth. | 6.1 |
2023-05-04 | CVE-2022-47449 | Cross-site Scripting vulnerability in Rextheme Cart Lift - Abandoned Cart Recovery for Woocommerce and EDD Unauth. | 6.1 |
2023-02-06 | CVE-2023-0174 | Cross-site Scripting vulnerability in Rextheme WP VR The WP VR WordPress plugin before 8.2.7 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks. | 5.4 |