Vulnerabilities > Spider Themes > Medium
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2024-11-02 | CVE-2024-9896 | Cross-site Scripting vulnerability in Spider-Themes BBP Core The BBP Core – Expand bbPress powered forums with useful features plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and including, 1.2.5. | 6.1 |
2024-07-02 | CVE-2024-3999 | Cross-site Scripting vulnerability in Spider-Themes Eazydocs The EazyDocs WordPress plugin before 2.5.0 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup) | 4.8 |
2024-02-12 | CVE-2024-0248 | Unspecified vulnerability in Spider-Themes Eazydocs The EazyDocs WordPress plugin before 2.4.0 re-introduced CVE-2023-6029 (https://wpscan.com/vulnerability/7a0aaf85-8130-4fd7-8f09-f8edc929597e/) in 2.3.8, allowing any authenticated users, such as subscriber to delete arbitrary posts, as well as add and delete documents/sections. | 4.3 |
2023-11-14 | CVE-2023-47549 | Unspecified vulnerability in Spider-Themes Eazydocs Unauth. | 6.1 |