Vulnerabilities > Techspawn
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2025-02-01 | CVE-2024-13341 | SQL Injection vulnerability in Techspawn Multiloca The MultiLoca - WooCommerce Multi Locations Inventory Management plugin for WordPress is vulnerable to SQL Injection via the 'data-id' parameter in all versions up to, and including, 4.1.11 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. | 6.5 |
2022-03-14 | CVE-2021-24959 | Unspecified vulnerability in Techspawn Wp-Email-Users The WP Email Users WordPress plugin through 1.7.6 does not escape the data_raw parameter in the weu_selected_users_1 AJAX action, available to any authenticated users, allowing them to perform SQL injection attacks. | 8.8 |