Vulnerabilities > Spider Themes > Medium

DATE CVE VULNERABILITY TITLE RISK
2024-11-02 CVE-2024-9896 Cross-site Scripting vulnerability in Spider-Themes BBP Core
The BBP Core – Expand bbPress powered forums with useful features plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and including, 1.2.5.
network
low complexity
spider-themes CWE-79
6.1
2024-07-02 CVE-2024-3999 Cross-site Scripting vulnerability in Spider-Themes Eazydocs
The EazyDocs WordPress plugin before 2.5.0 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)
network
low complexity
spider-themes CWE-79
4.8
2024-02-12 CVE-2024-0248 Unspecified vulnerability in Spider-Themes Eazydocs
The EazyDocs WordPress plugin before 2.4.0 re-introduced CVE-2023-6029 (https://wpscan.com/vulnerability/7a0aaf85-8130-4fd7-8f09-f8edc929597e/) in 2.3.8, allowing any authenticated users, such as subscriber to delete arbitrary posts, as well as add and delete documents/sections.
network
low complexity
spider-themes
4.3
2023-11-14 CVE-2023-47549 Unspecified vulnerability in Spider-Themes Eazydocs
Unauth.
network
low complexity
spider-themes
6.1