Vulnerabilities > Shooflysolutions

DATE CVE VULNERABILITY TITLE RISK
2024-02-05 CVE-2024-0254 Cross-site Scripting vulnerability in Shooflysolutions (Simply) Guest Author Name
The (Simply) Guest Author Name plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's post meta in all versions up to, and including, 4.34 due to insufficient input sanitization and output escaping on user supplied attributes.
network
low complexity
shooflysolutions CWE-79
5.4
2023-12-04 CVE-2023-5137 Cross-site Scripting vulnerability in Shooflysolutions Simply Excerpts
The Simply Excerpts WordPress plugin through 1.4 does not sanitize and escape some fields in the plugin settings, which could allow high-privilege users such as an administrator to inject arbitrary web scripts even when the unfiltered_html capability is disallowed (for example in a multisite setup).
network
low complexity
shooflysolutions CWE-79
4.8
2023-08-25 CVE-2023-32598 Unspecified vulnerability in Shooflysolutions Featured Image PRO Post Grid
Unauth.
network
low complexity
shooflysolutions
6.1