Filtered by vendor Wpmet Subscriptions
Total 25 CVE
CVE Vendors Products Updated CVSS v3.1
CVE-2023-46085 1 Wpmet 1 Wp Ultimate Review 2023-10-30 8.8 High
Cross-Site Request Forgery (CSRF) vulnerability in Wpmet Wp Ultimate Review plugin <= 2.2.4 versions.
CVE-2023-28751 1 Wpmet 1 Wp Ultimate Review 2023-06-28 4.8 Medium
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Wpmet Wp Ultimate Review plugin <= 2.0.3 versions.
CVE-2022-45371 1 Wpmet 1 Shopengine 2023-05-31 8.8 High
Cross-Site Request Forgery (CSRF) vulnerability in Wpmet ShopEngine plugin <= 4.1.1 versions.
CVE-2022-0788 1 Wpmet 1 Wp Fundraising Donation And Crowdfunding Platform 2022-10-05 9.8 Critical
The WP Fundraising Donation and Crowdfunding Platform WordPress plugin before 1.5.0 does not sanitise and escape a parameter before using it in a SQL statement via one of it's REST route, leading to an SQL injection exploitable by unauthenticated users
CVE-2021-24258 1 Wpmet 1 Elements Kit Elementor Addons 2021-05-11 5.4 Medium
The Elements Kit Lite and Elements Kit Pro WordPress Plugins before 2.2.0 have a number of widgets that are vulnerable to stored Cross-Site Scripting (XSS) by lower-privileged users such as contributors, all via a similar method.