Filtered by vendor Wpmet
Subscriptions
Total
25 CVE
CVE | Vendors | Products | Updated | CVSS v3.1 |
---|---|---|---|---|
CVE-2023-46085 | 1 Wpmet | 1 Wp Ultimate Review | 2023-10-30 | 8.8 High |
Cross-Site Request Forgery (CSRF) vulnerability in Wpmet Wp Ultimate Review plugin <= 2.2.4 versions. | ||||
CVE-2023-28751 | 1 Wpmet | 1 Wp Ultimate Review | 2023-06-28 | 4.8 Medium |
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Wpmet Wp Ultimate Review plugin <= 2.0.3 versions. | ||||
CVE-2022-45371 | 1 Wpmet | 1 Shopengine | 2023-05-31 | 8.8 High |
Cross-Site Request Forgery (CSRF) vulnerability in Wpmet ShopEngine plugin <= 4.1.1 versions. | ||||
CVE-2022-0788 | 1 Wpmet | 1 Wp Fundraising Donation And Crowdfunding Platform | 2022-10-05 | 9.8 Critical |
The WP Fundraising Donation and Crowdfunding Platform WordPress plugin before 1.5.0 does not sanitise and escape a parameter before using it in a SQL statement via one of it's REST route, leading to an SQL injection exploitable by unauthenticated users | ||||
CVE-2021-24258 | 1 Wpmet | 1 Elements Kit Elementor Addons | 2021-05-11 | 5.4 Medium |
The Elements Kit Lite and Elements Kit Pro WordPress Plugins before 2.2.0 have a number of widgets that are vulnerable to stored Cross-Site Scripting (XSS) by lower-privileged users such as contributors, all via a similar method. |