Vulnerabilities > Wpdeveloper > Medium

DATE CVE VULNERABILITY TITLE RISK
2023-12-11 CVE-2023-5749 Cross-site Scripting vulnerability in Wpdeveloper Embedpress
The EmbedPress WordPress plugin before 3.9.2 does not sanitise and escape user input before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin
network
low complexity
wpdeveloper CWE-79
6.1
2023-12-11 CVE-2023-5750 Cross-site Scripting vulnerability in Wpdeveloper Embedpress
The EmbedPress WordPress plugin before 3.9.2 does not sanitise and escape a parameter before outputting it back in the page containing a specific content, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin
network
low complexity
wpdeveloper CWE-79
6.1
2023-08-29 CVE-2023-32241 Cross-site Scripting vulnerability in Wpdeveloper Essential Addons for Elementor
Unauth.
network
low complexity
wpdeveloper CWE-79
6.1
2023-08-10 CVE-2023-4282 Missing Authorization vulnerability in Wpdeveloper Embedpress
The EmbedPress plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the 'admin_post_remove' and 'remove_private_data' functions in versions up to, and including, 3.8.2.
network
low complexity
wpdeveloper CWE-862
4.3
2023-08-10 CVE-2023-4283 Unspecified vulnerability in Wpdeveloper Embedpress
The EmbedPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'embedpress_calendar' shortcode in versions up to, and including, 3.8.2 due to insufficient input sanitization and output escaping on user supplied attributes.
network
low complexity
wpdeveloper
5.4
2023-07-01 CVE-2020-36744 Unspecified vulnerability in Wpdeveloper Notificationx
The NotificationX plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.8.2.
network
low complexity
wpdeveloper
4.3
2023-06-09 CVE-2023-2083 Unspecified vulnerability in Wpdeveloper Essential Blocks
The Essential Blocks plugin for WordPress is vulnerable to unauthorized use of functionality due to a missing capability check on the save function in versions up to, and including, 4.0.6.
network
low complexity
wpdeveloper
4.3
2023-06-09 CVE-2023-2084 Unspecified vulnerability in Wpdeveloper Essential Blocks
The Essential Blocks plugin for WordPress is vulnerable to unauthorized use of functionality due to a missing capability check on the get function in versions up to, and including, 4.0.6.
network
low complexity
wpdeveloper
4.3
2023-06-09 CVE-2023-2085 Unspecified vulnerability in Wpdeveloper Essential Blocks
The Essential Blocks plugin for WordPress is vulnerable to unauthorized use of functionality due to a missing capability check on the templates function in versions up to, and including, 4.0.6.
network
low complexity
wpdeveloper
4.3
2023-06-09 CVE-2023-2086 Unspecified vulnerability in Wpdeveloper Essential Blocks
The Essential Blocks plugin for WordPress is vulnerable to unauthorized use of functionality due to a missing capability check on the template_count function in versions up to, and including, 4.0.6.
network
low complexity
wpdeveloper
4.3