Vulnerabilities > Themeum > WP Crowdfunding > 2.1.2

DATE CVE VULNERABILITY TITLE RISK
2024-01-15 CVE-2023-6163 Cross-site Scripting vulnerability in Themeum WP Crowdfunding
The WP Crowdfunding WordPress plugin before 2.1.10 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)
network
low complexity
themeum CWE-79
4.8
2024-01-08 CVE-2023-6161 Cross-site Scripting vulnerability in Themeum WP Crowdfunding
The WP Crowdfunding WordPress plugin before 2.1.9 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin
network
low complexity
themeum CWE-79
6.1
2023-12-28 CVE-2023-50859 Cross-site Scripting vulnerability in Themeum WP Crowdfunding
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Themeum WP Crowdfunding allows Stored XSS.This issue affects WP Crowdfunding: from n/a through 2.1.6.
network
low complexity
themeum CWE-79
5.4
2023-12-11 CVE-2023-5757 Cross-site Scripting vulnerability in Themeum WP Crowdfunding
The WP Crowdfunding WordPress plugin before 2.1.8 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)
network
low complexity
themeum CWE-79
4.8