Vulnerabilities > Winwar

DATE CVE VULNERABILITY TITLE RISK
2023-12-21 CVE-2023-28421 Information Exposure vulnerability in Winwar WP Email Capture
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Winwar Media WordPress Email Marketing Plugin – WP Email Capture.This issue affects WordPress Email Marketing Plugin – WP Email Capture: from n/a through 3.10.
network
low complexity
winwar CWE-200
7.5
2023-05-23 CVE-2023-23724 Cross-Site Request Forgery (CSRF) vulnerability in Winwar WP Email Capture
Cross-Site Request Forgery (CSRF) vulnerability in Winwar Media WP Email Capture plugin <= 3.9.3 versions.
network
low complexity
winwar CWE-352
8.8
2023-05-02 CVE-2023-23723 Cross-site Scripting vulnerability in Winwar WP Email Capture
Auth.
network
low complexity
winwar CWE-79
4.8
2023-04-25 CVE-2023-24005 Cross-site Scripting vulnerability in Winwar Inline Tweet Sharer
Auth.
network
low complexity
winwar CWE-79
4.8
2023-03-23 CVE-2023-23722 Cross-site Scripting vulnerability in Winwar WP Ebay Product Feeds
Auth.
network
low complexity
winwar CWE-79
4.8
2023-03-23 CVE-2023-23728 Cross-site Scripting vulnerability in Winwar WP Flipclock
Auth.
network
low complexity
winwar CWE-79
5.4
2019-12-27 CVE-2014-4525 Cross-site Scripting vulnerability in Winwar WP Ebay Product Feeds
Cross-site scripting (XSS) vulnerability in magpie/scripts/magpie_slashbox.php in the Ebay Feeds for WordPress plugin 1.1 and earlier for WordPress allows remote attackers to inject arbitrary web script or HTML via the rss_url parameter.
network
low complexity
winwar CWE-79
6.1