Vulnerabilities > Stpetedesign

DATE CVE VULNERABILITY TITLE RISK
2023-08-17 CVE-2023-30874 Cross-site Scripting vulnerability in Stpetedesign GPS Plotter
Auth.
network
low complexity
stpetedesign CWE-79
4.8
2023-07-10 CVE-2023-2028 Unspecified vulnerability in Stpetedesign Call NOW Accessibility Button 1.0.2
The Call Now Accessibility Button WordPress plugin before 1.1 does not properly sanitize some of its settings, which could allow high-privilege users to perform Stored Cross-Site Scripting (XSS) attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).
network
low complexity
stpetedesign
4.8
2023-07-10 CVE-2023-2635 Unspecified vulnerability in Stpetedesign Call NOW Accessibility Button 1.0.2
The Call Now Accessibility Button WordPress plugin before 1.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)
network
low complexity
stpetedesign
4.8
2023-06-12 CVE-2023-28933 Cross-site Scripting vulnerability in Stpetedesign Call NOW Accessibility Button
Auth.
network
low complexity
stpetedesign CWE-79
4.8