Vulnerabilities > WOW Company

DATE CVE VULNERABILITY TITLE RISK
2024-09-04 CVE-2024-6926 SQL Injection vulnerability in Wow-Company Viral Signup
The Viral Signup WordPress plugin through 2.1 does not properly sanitise and escape a parameter before using it in a SQL statement via an AJAX action available to unauthenticated users, leading to a SQL injection
network
low complexity
wow-company CWE-89
critical
9.8
2024-08-29 CVE-2024-6927 Cross-site Scripting vulnerability in Wow-Company Viral Signup
The Viral Signup WordPress plugin through 2.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)
network
low complexity
wow-company CWE-79
4.8
2024-06-04 CVE-2024-35629 Inclusion of Functionality from Untrusted Control Sphere vulnerability in Wow-Company Easy Digital Downloads 1.0.2
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Wow-Company Easy Digital Downloads – Recent Purchases allows PHP Remote File Inclusion.This issue affects Easy Digital Downloads – Recent Purchases: from n/a through 1.0.2.
network
low complexity
wow-company CWE-829
critical
9.8
2024-06-04 CVE-2024-35634 Path Traversal vulnerability in Wow-Company Woocommerce - Recent Purchases 1.0.1
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Wow-Company Woocommerce – Recent Purchases allows PHP Local File Inclusion.This issue affects Woocommerce – Recent Purchases: from n/a through 1.0.1.
network
low complexity
wow-company CWE-22
4.9
2024-01-23 CVE-2024-0703 Cross-site Scripting vulnerability in Wow-Company Sticky Buttons
The Sticky Buttons – floating buttons builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via sticky URLs in all versions up to, and including, 3.2.2 due to insufficient input sanitization and output escaping.
network
low complexity
wow-company CWE-79
4.8
2024-01-05 CVE-2023-52149 Cross-Site Request Forgery (CSRF) vulnerability in Wow-Company Floating Button
Cross-Site Request Forgery (CSRF) vulnerability in Wow-Company Floating Button.This issue affects Floating Button: from n/a through 6.0.
network
low complexity
wow-company CWE-352
8.8
2023-12-18 CVE-2023-49155 Cross-Site Request Forgery (CSRF) vulnerability in Wow-Company Button Generator
Cross-Site Request Forgery (CSRF) vulnerability in Wow-Company Button Generator – easily Button Builder.This issue affects Button Generator – easily Button Builder: from n/a through 2.3.8.
network
low complexity
wow-company CWE-352
8.8
2023-11-12 CVE-2023-27418 Cross-Site Request Forgery (CSRF) vulnerability in Wow-Company Side Menu Lite
Cross-Site Request Forgery (CSRF) vulnerability in Wow-Company Side Menu Lite – add sticky fixed buttons plugin <= 4.0 versions.
network
low complexity
wow-company CWE-352
8.8
2023-09-27 CVE-2023-5161 Unspecified vulnerability in Wow-Company Modal Window
The Modal Window plugin for WordPress is vulnerable to Stored Cross-Site Scripting via shortcodes in versions up to, and including, 5.3.5 due to insufficient input sanitization and output escaping on user supplied attributes.
network
low complexity
wow-company
5.4
2023-09-11 CVE-2023-4022 Unspecified vulnerability in Wow-Company Herd Effects
The Herd Effects WordPress plugin before 5.2.3 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)
network
low complexity
wow-company
4.8