Vulnerabilities > Shareaholic > Similar Posts > 2.6.1.2

DATE CVE VULNERABILITY TITLE RISK
2023-04-24 CVE-2022-41612 Cross-site Scripting vulnerability in Shareaholic Similar Posts
Auth.
network
low complexity
shareaholic CWE-79
4.8
2021-11-08 CVE-2021-24537 Unspecified vulnerability in Shareaholic Similar Posts
The Similar Posts WordPress plugin through 3.1.5 allow high privilege users to execute arbitrary PHP code in an hardened environment (ie with DISALLOW_FILE_EDIT, DISALLOW_FILE_MODS and DISALLOW_UNFILTERED_HTML set to true) via the 'widget_rrm_similar_posts_condition' widget setting of the plugin.
network
shareaholic
6.0