Vulnerabilities (CVE)

Filtered by vendor Wpdeveloper Subscribe
Total 125 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2021-24812 1 Wpdeveloper 1 Betterlinks 2021-11-24 3.5 LOW 5.4 MEDIUM
The BetterLinks WordPress plugin before 1.2.6 does not sanitise and escape some of imported link fields, which could lead to Stored Cross-Site Scripting issues when an admin import a malicious CSV.
CVE-2021-24633 1 Wpdeveloper 1 Countdown Block 2021-11-05 4.0 MEDIUM 4.3 MEDIUM
The Countdown Block WordPress plugin before 1.1.2 does not have authorisation in the eb_write_block_css AJAX action, which allows any authenticated user, such as Subscriber, to modify post contents displayed to users.
CVE-2021-24255 1 Wpdeveloper 1 Essential Addons For Elementor 2021-05-11 3.5 LOW 5.4 MEDIUM
The Essential Addons for Elementor Lite WordPress Plugin before 4.5.4 has two widgets that are vulnerable to stored Cross-Site Scripting (XSS) by lower-privileged users such as contributors, both via a similar method.
CVE-2017-18504 1 Wpdeveloper 1 Twitter Cards Meta 2019-08-16 6.8 MEDIUM 8.8 HIGH
The twitter-cards-meta plugin before 2.5.0 for WordPress has CSRF.
CVE-2017-18503 1 Wpdeveloper 1 Twitter Cards Meta 2019-08-16 4.3 MEDIUM 6.1 MEDIUM
The twitter-cards-meta plugin before 2.5.0 for WordPress has XSS.