Vulnerabilities > WOW Company
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2024-09-04 | CVE-2024-6926 | SQL Injection vulnerability in Wow-Company Viral Signup The Viral Signup WordPress plugin through 2.1 does not properly sanitise and escape a parameter before using it in a SQL statement via an AJAX action available to unauthenticated users, leading to a SQL injection | 9.8 |
2024-08-29 | CVE-2024-6927 | Cross-site Scripting vulnerability in Wow-Company Viral Signup The Viral Signup WordPress plugin through 2.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup) | 4.8 |
2024-06-04 | CVE-2024-35629 | Inclusion of Functionality from Untrusted Control Sphere vulnerability in Wow-Company Easy Digital Downloads 1.0.2 Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Wow-Company Easy Digital Downloads – Recent Purchases allows PHP Remote File Inclusion.This issue affects Easy Digital Downloads – Recent Purchases: from n/a through 1.0.2. | 9.8 |
2024-06-04 | CVE-2024-35634 | Path Traversal vulnerability in Wow-Company Woocommerce - Recent Purchases 1.0.1 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Wow-Company Woocommerce – Recent Purchases allows PHP Local File Inclusion.This issue affects Woocommerce – Recent Purchases: from n/a through 1.0.1. | 4.9 |
2024-01-23 | CVE-2024-0703 | Cross-site Scripting vulnerability in Wow-Company Sticky Buttons The Sticky Buttons – floating buttons builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via sticky URLs in all versions up to, and including, 3.2.2 due to insufficient input sanitization and output escaping. | 4.8 |
2024-01-05 | CVE-2023-52149 | Cross-Site Request Forgery (CSRF) vulnerability in Wow-Company Floating Button Cross-Site Request Forgery (CSRF) vulnerability in Wow-Company Floating Button.This issue affects Floating Button: from n/a through 6.0. | 8.8 |
2023-12-18 | CVE-2023-49155 | Cross-Site Request Forgery (CSRF) vulnerability in Wow-Company Button Generator Cross-Site Request Forgery (CSRF) vulnerability in Wow-Company Button Generator – easily Button Builder.This issue affects Button Generator – easily Button Builder: from n/a through 2.3.8. | 8.8 |
2023-11-12 | CVE-2023-27418 | Cross-Site Request Forgery (CSRF) vulnerability in Wow-Company Side Menu Lite Cross-Site Request Forgery (CSRF) vulnerability in Wow-Company Side Menu Lite – add sticky fixed buttons plugin <= 4.0 versions. | 8.8 |
2023-09-27 | CVE-2023-5161 | Unspecified vulnerability in Wow-Company Modal Window The Modal Window plugin for WordPress is vulnerable to Stored Cross-Site Scripting via shortcodes in versions up to, and including, 5.3.5 due to insufficient input sanitization and output escaping on user supplied attributes. | 5.4 |
2023-09-11 | CVE-2023-4022 | Unspecified vulnerability in Wow-Company Herd Effects The Herd Effects WordPress plugin before 5.2.3 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup) | 4.8 |