Vulnerabilities > Wpcodeus

DATE CVE VULNERABILITY TITLE RISK
2024-10-28 CVE-2024-50458 Cross-site Scripting vulnerability in Wpcodeus Advanced Sermons
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in WP Codeus Advanced Sermons allows Stored XSS.This issue affects Advanced Sermons: from n/a through 3.4.
network
low complexity
wpcodeus CWE-79
5.4
2024-09-06 CVE-2024-7599 Cross-site Scripting vulnerability in Wpcodeus Advanced Sermons
The Advanced Sermons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘sermon_video_embed’ parameter in all versions up to, and including, 3.3 due to insufficient input sanitization and output escaping.
network
low complexity
wpcodeus CWE-79
5.4