Vulnerabilities > Wpopal

DATE CVE VULNERABILITY TITLE RISK
2024-01-19 CVE-2022-40700 Server-Side Request Forgery (SSRF) vulnerability in multiple products
Server-Side Request Forgery (SSRF) vulnerability in Montonio Montonio for WooCommerce, Wpopal Wpopal Core Features, AMO for WP – Membership Management ArcStone wp-amo, Long Watch Studio WooVirtualWallet – A virtual wallet for WooCommerce, Long Watch Studio WooVIP – Membership plugin for WordPress and WooCommerce, Long Watch Studio WooSupply – Suppliers, Supply Orders and Stock Management, Squidesma Theme Minifier, Paul Clark Styles styles, Designmodo Inc.
9.8
2023-07-01 CVE-2021-4388 Missing Authorization vulnerability in Wpopal Opal Estate 1.6.11
The Opal Estate plugin for WordPress is vulnerable to featured property modifications in versions up to, and including, 1.6.11.
network
low complexity
wpopal CWE-862
5.3
2023-07-01 CVE-2021-4387 Unspecified vulnerability in Wpopal Opal Estate 1.6.11
The Opal Estate plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.6.11.
network
low complexity
wpopal
8.8
2022-05-19 CVE-2022-29449 Cross-site Scripting vulnerability in Wpopal Opal Hotel Room Booking
Authenticated (contributor or higher user role) Stored Cross-Site Scripting (XSS) vulnerability in Opal Hotel Room Booking plugin <= 1.2.7 at WordPress.
network
wpopal CWE-79
3.5