Vulnerabilities > Spider Themes > Eazydocs > Medium
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2024-07-02 | CVE-2024-3999 | Cross-site Scripting vulnerability in Spider-Themes Eazydocs The EazyDocs WordPress plugin before 2.5.0 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup) | 4.8 |
2024-02-12 | CVE-2024-0248 | Unspecified vulnerability in Spider-Themes Eazydocs The EazyDocs WordPress plugin before 2.4.0 re-introduced CVE-2023-6029 (https://wpscan.com/vulnerability/7a0aaf85-8130-4fd7-8f09-f8edc929597e/) in 2.3.8, allowing any authenticated users, such as subscriber to delete arbitrary posts, as well as add and delete documents/sections. | 4.3 |
2023-11-14 | CVE-2023-47549 | Unspecified vulnerability in Spider-Themes Eazydocs Unauth. | 6.1 |