Vulnerabilities > Tipsandtricks HQ > High

DATE CVE VULNERABILITY TITLE RISK
2024-07-15 CVE-2024-6075 Cross-Site Request Forgery (CSRF) vulnerability in Tipsandtricks-Hq WP Estore
The wp-cart-for-digital-products WordPress plugin before 8.5.5 does not have CSRF checks in some places, which could allow attackers to make logged in users perform unwanted actions via CSRF attacks
network
low complexity
tipsandtricks-hq CWE-352
8.8
2023-05-03 CVE-2023-22691 Cross-Site Request Forgery (CSRF) vulnerability in Tipsandtricks-Hq Category Specific RSS Feed Subscription
Cross-Site Request Forgery (CSRF) vulnerability in Tips and Tricks HQ, Ruhul Amin Category Specific RSS feed Subscription plugin <= v2.1 versions.
network
low complexity
tipsandtricks-hq CWE-352
8.8
2022-11-22 CVE-2022-44737 Cross-Site Request Forgery (CSRF) vulnerability in Tipsandtricks-Hq ALL in ONE WP Security & Firewall
Multiple Cross-Site Request Forgery vulnerabilities in All-In-One Security (AIOS) – Security and Firewall (WordPress plugin) <= 5.1.0 on WordPress.
network
low complexity
tipsandtricks-hq CWE-352
8.8
2021-11-08 CVE-2021-24695 Forced Browsing vulnerability in Tipsandtricks-Hq Simple Download Monitor
The Simple Download Monitor WordPress plugin before 3.9.6 saves logs in a predictable location, and does not have any authentication or authorisation in place to prevent unauthenticated users to download and read the logs containing Sensitive Information such as IP Addresses and Usernames
network
low complexity
tipsandtricks-hq CWE-425
7.5
2019-08-14 CVE-2016-10888 SQL Injection vulnerability in ONE WP Security & Firewall
The all-in-one-wp-security-and-firewall plugin before 4.0.7 for WordPress has multiple SQL injection issues.
network
low complexity
tipsandtricks-hq CWE-89
7.5
2019-08-14 CVE-2016-10887 SQL Injection vulnerability in ONE WP Security & Firewall
The all-in-one-wp-security-and-firewall plugin before 4.0.9 for WordPress has multiple SQL injection issues.
network
low complexity
tipsandtricks-hq CWE-89
7.5
2019-08-14 CVE-2015-9310 SQL Injection vulnerability in ONE WP Security & Firewall
The all-in-one-wp-security-and-firewall plugin before 3.9.1 for WordPress has multiple SQL injection issues.
network
low complexity
tipsandtricks-hq CWE-89
7.5