Vulnerabilities > Tipsandtricks HQ > Medium

DATE CVE VULNERABILITY TITLE RISK
2023-01-23 CVE-2022-4672 Unspecified vulnerability in Tipsandtricks-Hq Wordpress Simple Paypal Shopping Cart
The WordPress Simple Shopping Cart WordPress plugin before 4.6.2 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as admins.
network
low complexity
tipsandtricks-hq
5.4
2023-01-16 CVE-2022-4465 Unspecified vulnerability in Tipsandtricks-Hq WP Video Lightbox
The WP Video Lightbox WordPress plugin before 1.9.7 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as admin.
network
low complexity
tipsandtricks-hq
5.4
2022-11-28 CVE-2022-3822 Unspecified vulnerability in Tipsandtricks-Hq Donations VIA Paypal
The Donations via PayPal WordPress plugin before 1.9.9 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).
network
low complexity
tipsandtricks-hq
4.8
2022-06-08 CVE-2022-1695 Cross-Site Request Forgery (CSRF) vulnerability in Tipsandtricks-Hq WP Simple Adsense Insertion
The WP Simple Adsense Insertion WordPress plugin before 2.1 does not perform CSRF checks on updates to its admin page, allowing an attacker to trick a logged in user to manipulate ads and inject arbitrary javascript via submitting a form.
4.3
2022-03-14 CVE-2021-24692 Path Traversal vulnerability in Tipsandtricks-Hq Simple Download Monitor
The Simple Download Monitor WordPress plugin before 3.9.5 allows users with a role as low as Contributor to download any file on the web server (such as wp-config.php) via a path traversal vector.
network
low complexity
tipsandtricks-hq CWE-22
4.0
2022-01-24 CVE-2021-24696 Cross-Site Request Forgery (CSRF) vulnerability in Tipsandtricks-Hq Simple Download Monitor
The Simple Download Monitor WordPress plugin before 3.9.9 does not enforce nonce checks, which could allow attackers to perform CSRF attacks to 1) make admins export logs to exploit a separate log disclosure vulnerability (fixed in 3.9.6), 2) delete logs (fixed in 3.9.9), 3) remove thumbnail image from downloads
6.8
2021-11-08 CVE-2021-24693 Cross-site Scripting vulnerability in Tipsandtricks-Hq Simple Download Monitor
The Simple Download Monitor WordPress plugin before 3.9.5 does not escape the "File Thumbnail" post meta before outputting it in some pages, which could allow users with a role as low as Contributor to perform Stored Cross-Site Scripting attacks.
6.0
2021-11-08 CVE-2021-24697 Cross-site Scripting vulnerability in Tipsandtricks-Hq Simple Download Monitor
The Simple Download Monitor WordPress plugin before 3.9.5 does not escape the 1) sdm_active_tab GET parameter and 2) sdm_stats_start_date/sdm_stats_end_date POST parameters before outputting them back in attributes, leading to Reflected Cross-Site Scripting issues
4.3
2021-11-08 CVE-2021-24698 Unspecified vulnerability in Tipsandtricks-Hq Simple Download Monitor
The Simple Download Monitor WordPress plugin before 3.9.6 allows users with a role as low as Contributor to remove thumbnails from downloads they do not own, even if they cannot normally edit the download.
network
low complexity
tipsandtricks-hq
4.0
2021-11-01 CVE-2021-24799 Cross-Site Request Forgery (CSRF) vulnerability in Tipsandtricks-Hq FAR Future Expiry Header
The Far Future Expiry Header WordPress plugin before 1.5 does not have CSRF check when saving its settings, which could allow attackers to make a logged in admin change them via a CSRF attack.
4.3