Vulnerabilities > WEB Settler

DATE CVE VULNERABILITY TITLE RISK
2023-11-08 CVE-2023-47227 Cross-site Scripting vulnerability in Web-Settler Social Feed | ALL Social Media in ONE Place 1.5.4.6
Auth.
network
low complexity
web-settler CWE-79
4.8
2023-11-08 CVE-2023-47228 Cross-site Scripting vulnerability in Web-Settler Layer Slider
Auth.
network
low complexity
web-settler CWE-79
4.8
2023-11-07 CVE-2023-23796 Improper Neutralization of Formula Elements in a CSV File vulnerability in Web-Settler Form Builder
Improper Neutralization of Formula Elements in a CSV File vulnerability in Muneeb Form Builder | Create Responsive Contact Forms.This issue affects Form Builder | Create Responsive Contact Forms: from n/a through 1.9.9.0.
network
low complexity
web-settler CWE-1236
critical
9.8
2023-11-07 CVE-2023-5661 Cross-site Scripting vulnerability in Web-Settler Social Feed
The Social Feed plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'socialfeed' shortcode in all versions up to, and including, 1.5.4.6 due to insufficient input sanitization and output escaping on user supplied attributes.
network
low complexity
web-settler CWE-79
5.4
2023-09-01 CVE-2023-24412 Cross-site Scripting vulnerability in Web-Settler Image Social Feed 1.7.6
Auth.
network
low complexity
web-settler CWE-79
4.8
2023-08-10 CVE-2023-23798 Cross-site Scripting vulnerability in Web-Settler Layer Slider
Auth.
network
low complexity
web-settler CWE-79
5.4
2023-07-11 CVE-2023-23671 Cross-Site Request Forgery (CSRF) vulnerability in Web-Settler Layer Slider
Cross-Site Request Forgery (CSRF) vulnerability in Muneeb Layer Slider plugin <= 1.1.9.7 versions.
network
low complexity
web-settler CWE-352
6.5
2023-06-22 CVE-2023-23795 Cross-Site Request Forgery (CSRF) vulnerability in Web-Settler Form Builder
Cross-Site Request Forgery (CSRF) vulnerability in Muneeb Form Builder plugin <= 1.9.9.0 versions.
network
low complexity
web-settler CWE-352
8.8
2023-05-10 CVE-2022-46861 Cross-site Scripting vulnerability in Web-Settler Custom Login Page Styler
Auth.
network
low complexity
web-settler CWE-79
4.8
2022-04-04 CVE-2021-36851 Cross-site Scripting vulnerability in Web-Settler Testimonial Slider
Authenticated (editor or higher user role) Cross-Site Scripting (XSS) vulnerability in Web-Settler Testimonial Slider – Free Testimonials Slider Plugin (WordPress plugin) via parameters mpsp_posts_bg_color, mpsp_posts_description_color, mpsp_slide_nav_button_color.
network
low complexity
web-settler CWE-79
5.4